Vulnerabilities
CVE-2025-30035 - Lack of API authentication allowing session generation for any user
CVE ID : CVE-2025-30035 Published : March 2, 2026, 12:16 p.m. | 1 hour ago Description : The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the privileges of the targeted user. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...