SQL Injection Vulnerability in ReturnUserUnitsXML.pl Service by Vendor
CVE-2025-30060
6.9MEDIUM
What is CVE-2025-30060?
The ReturnUserUnitsXML.pl service includes a vulnerability in the 'getUserInfo' function, which is susceptible to SQL injection via the 'UserID' parameter. Attackers exploiting this flaw could manipulate database queries, potentially leading to unauthorized access to sensitive data or system compromise. Organizations using this service should implement measures to sanitize input and mitigate risks associated with SQL injection.
Affected Version(s)
CGM CLININET 0 < 2024.MS4