PT-2025-17858 · Itc Systems · Itc Systems Multiplan/Matrix Onecard

Yoshik0Xf6

·

Published

2025-04-24

·

Updated

2025-04-25

·

CVE-2025-29529

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ITC Systems Multiplan/Matrix OneCard platform version 3.7.4.1002
Description The issue is related to a SQL injection vulnerability. It affects the Forgotpassword.aspx component.
Recommendations For version 3.7.4.1002, consider restricting access to the Forgotpassword.aspx component until a patch is available. Avoid using the Forgotpassword.aspx component to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-29529

Affected Products

Itc Systems Multiplan/Matrix Onecard