Back to Database
Status published
Medium
CVE-2025-30061
SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameter
Vulnerability Description
In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30061
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maciej Kazulak
More from CGM
View All →CVE-2025-58406
Lack of HTTP Response Headers
Medium
5.3
CVE-2025-58405
Lack of protection mechanisms against Clickjacking attacks
Medium
5.3
CVE-2025-58402
Insecure Direct Object Reference Message ID
High
7.1
CVE-2025-30064
Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key
High
8.8
CVE-2025-30063
Excessive permissions on configuration files containing database logins and passwords
Critical
9.4
Affected Vendor
Affected Software
CGM CLININET
Vulnerable Versions:
0
Timeline
Official Publish:
August 27th, 2025
Last Modified:
August 27th, 2025
Added to House:
July 22nd, 2026