CVE-2025-10350
Last modified
CVE-2025-10350 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.
Metrics
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-10350?
How severe is CVE-2025-10350?
How do I fix CVE-2025-10350?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10343HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10344HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10345HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10346HTML injection vulnerability in Perfex CRM v3.2.1 consisting…6.1
- CVE-2025-10348URVE Smart Office is vulnerable to Stored XSS in report prob…5.1
- CVE-2025-1035Improper Limitation of a Pathname to a Restricted Directory …5.7
- CVE-2025-10351SQL injection vulnerability based on the melis-cms module of…9.3
- CVE-2025-10352Vulnerability in the melis-core module of Melis Technology's…9.3
- CVE-2025-10353File upload leading to remote code execution (RCE) in the “m…9.3
- CVE-2025-10354Cross-Site Scripting (XSS) vulnerability reflected in Semant…5.1
- CVE-2025-10355Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. Th…5.1
- CVE-2025-10357The Simple SEO WordPress plugin before 2.0.32 does not sanit…6.1
Are you affected by CVE-2025-10350?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
