PT-2025-43181 · Cozy Vision · Sms Alert Order Notifications

Chuongvn

·

Published

2025-10-22

·

Updated

2025-11-18

·

CVE-2025-49915

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cozy Vision SMS Alert Order Notifications versions through 3.8.5
Description A flaw exists in Cozy Vision SMS Alert Order Notifications that allows for SQL Injection. This issue is due to improper neutralization of special elements within SQL commands. The vulnerability affects the SMS Alert Order Notifications functionality.
Recommendations Update to a version later than 3.8.5.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-49915

Affected Products

Sms Alert Order Notifications