Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-29980

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:centralsquare:etrakit.net:3.2.1.77:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
11 месяцев назад

A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89