PT-2025-44587 · Abis Technology · Bapsis

Published

2025-10-31

·

Updated

2025-10-31

·

CVE-2025-6520

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Abis Technology BAPSIS versions prior to 202510271606
Description An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') issue exists in Abis Technology BAPSIS, allowing for Blind SQL Injection. This allows unauthenticated attackers to potentially extract the full database using time-based techniques. The vulnerability is present in versions before 202510271606.
Recommendations Versions prior to 202510271606 should be updated.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-6520

Affected Products

Bapsis