PT-2025-10441 · At Software Solutions · At Software Solutions Atsvd

Y4G0

+1

·

Published

2025-03-09

·

Updated

2025-03-14

·

CVE-2025-2113

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AT Software Solutions ATSVD versions up to 3.4.1
Description A critical issue affects some unknown functionality of the component Esqueceu a senha. The manipulation of the txtCPF argument leads to SQL injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations Upgrading to version 3.4.2 is able to address this issue. It is recommended to upgrade the affected component. As a temporary workaround, consider restricting the use of the txtCPF argument to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2113

Affected Products

At Software Solutions Atsvd