CVE-2025-58405
Plain English Summary
AI-powered analysis for quick understanding
An attacker can trick users into interacting with the CGM CLININET application by embedding it in a hidden frame on a malicious website, potentially leading users to perform unintended actions without their knowledge. This vulnerability exists because the application lacks protections against clickjacking, meaning it doesn't have the necessary security measures in place to prevent such attacks.
Technical Description
The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended actions, including potentially bypassing CSRF/XSRF defenses.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 2, 2026
about 1 month ago
Last Modified
Mar 2, 2026
about 1 month ago