PT-2025-28459 · Abis · Adjutant Core Accounting Erp
Cmoncrook
·
Published
2025-07-08
·
Updated
2025-07-08
·
CVE-2025-29267
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Abis, Inc Adjutant Core Accounting ERP version v.PreBeta250F
Description:
The issue allows a remote attacker to obtain sensitive information via the
cid parameter in the GET request. This is a SQL Injection vulnerability, which means an attacker can inject malicious SQL code to manipulate the database and extract sensitive data.Recommendations:
For Abis, Inc Adjutant Core Accounting ERP version v.PreBeta250F, consider restricting access to the vulnerable
cid parameter in the GET request until a patch is available. As a temporary workaround, avoid using the cid parameter in affected API endpoints to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adjutant Core Accounting Erp