216.73.216.36

CVE-2025-58405

· Published 02/03/2026 12:16 · Modified 02/03/2026 20:29

Labels: CVE-2025-58405 2026-03-02CVE-2025-58405CWE-1021[email protected]

Essential information

Published
02/03/2026 12:16
Modified
02/03/2026 20:29
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended actions, including potentially bypassing CSRF/XSRF defenses.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cgm / clininet cpe:2.3:a:cgm:clininet:*:*:*:*:*:*:*:*

References