PT-2025-28459 · Abis · Adjutant Core Accounting Erp

·

CVE-2025-29267

·

Published

2025-07-08

·

Updated

2025-07-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Abis, Inc Adjutant Core Accounting ERP version v.PreBeta250F
Description: The issue allows a remote attacker to obtain sensitive information via the cid parameter in the GET request. This is a SQL Injection vulnerability, which means an attacker can inject malicious SQL code to manipulate the database and extract sensitive data.
Recommendations: For Abis, Inc Adjutant Core Accounting ERP version v.PreBeta250F, consider restricting access to the vulnerable cid parameter in the GET request until a patch is available. As a temporary workaround, avoid using the cid parameter in affected API endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29267

Affected Products

Adjutant Core Accounting Erp