PT-2025-10441 · At Software Solutions · At Software Solutions Atsvd
Y4G0
+1
·
Publicado
2025-03-09
·
Atualizado
2025-03-14
·
CVE-2025-2113
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AT Software Solutions ATSVD versions up to 3.4.1
Description
A critical issue affects some unknown functionality of the component Esqueceu a senha. The manipulation of the
txtCPF argument leads to SQL injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Recommendations
Upgrading to version 3.4.2 is able to address this issue. It is recommended to upgrade the affected component. As a temporary workaround, consider restricting the use of the
txtCPF argument to minimize the risk of exploitation.Exploit
Correção
Special Elements Injection
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
At Software Solutions Atsvd