Stored XSS Vulnerability in OddziaĆ Module by Vendor
CVE-2025-30036
8.8HIGH
What is CVE-2025-30036?
The OddziaĆ module contains a stored cross-site scripting (XSS) vulnerability in the death diagnosis description field. This security flaw allows unauthorized execution of arbitrary JavaScript code, which can lead to session hijacking of other users' accounts. Attackers can exploit this vulnerability to gain elevated privileges, potentially leading to administrative access and unauthorized manipulation of sensitive data within the application.
Affected Version(s)
CGM CLININET 0 < 2024.MS4