PT-2025-10441 · At Software Solutions · At Software Solutions Atsvd
Y4G0
+1
·
Published
2025-03-09
·
Updated
2025-03-14
·
CVE-2025-2113
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AT Software Solutions ATSVD versions up to 3.4.1
Description
A critical issue affects some unknown functionality of the component Esqueceu a senha. The manipulation of the
txtCPF argument leads to SQL injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Recommendations
Upgrading to version 3.4.2 is able to address this issue. It is recommended to upgrade the affected component. As a temporary workaround, consider restricting the use of the
txtCPF argument to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
At Software Solutions Atsvd