Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.pl/en/posts/2025/08/CVE-2025-2313/ |
![]() ![]() |
History
Wed, 27 Aug 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cgm
Cgm clininet |
|
Vendors & Products |
Cgm
Cgm clininet |
Wed, 27 Aug 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 27 Aug 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights. | |
Title | Stored XSS permitting session takeover of arbitrary user | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-08-27T16:21:33.671Z
Reserved: 2025-03-14T14:54:23.998Z
Link: CVE-2025-30036

Updated: 2025-08-27T16:21:30.257Z

Status : Received
Published: 2025-08-27T11:15:32.353
Modified: 2025-08-27T11:15:32.353
Link: CVE-2025-30036

No data.