The CGM CLININET application uses direct, sequential...
High severity
Unreviewed
Published
Mar 2, 2026
to the GitHub Advisory Database
•
Updated Mar 9, 2026
Description
Published by the National Vulnerability Database
Mar 2, 2026
Published to the GitHub Advisory Database
Mar 2, 2026
Last updated
Mar 9, 2026
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.
References