Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Malik Tawfiq

#25894of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2025-13576
9.8
2025-03-28
Epicor · Epicor Hcm · CVE-2025-22953
**Name of the Vulnerable Software and Affected Versions** Epicor HCM version 2021 1.9 **Description** A SQL injection issue exists, specifically in the `filter` parameter of the "JsonFetcher.svc" endpoint. An attacker can exploit this by injecting malicious SQL payloads into the `filter` parameter, enabling the unauthorized execution of arbitrary SQL commands on the backend database. If certain features, like `xp cmdshell`, are enabled, this may lead to remote code execution. **Recommendations** For Epicor HCM version 2021 1.9, consider disabling the `JsonFetcher.svc` endpoint or restricting access to the `filter` parameter until a patch is available. Avoid using the `filter` parameter in the affected endpoint until the issue is resolved.