PT-2025-43604 · Basis Technology · Netty Erp

Murat Erdemi̇r

·

Published

2025-10-24

·

Updated

2026-06-04

·

CVE-2025-11253

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aksis Technology Inc. Netty ERP versions prior to V.1.1000
Description Netty ERP contains a flaw due to improper neutralization of special elements used in an SQL command, leading to a SQL Injection issue. This allows for the potential execution of arbitrary SQL commands. The issue does not require login, potentially allowing unauthenticated attackers to compromise the system. The vulnerability could lead to data theft or system compromise.
Recommendations Versions prior to V.1.1000 should be updated to V.1.1000 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11253

Affected Products

Netty Erp