PT-2025-45420 · Paperwork+1 · Paperwork+1

Murat Erdemi̇r

·

Published

2025-11-07

·

Updated

2025-11-12

·

CVE-2025-10968

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaperWork versions 6.1.0.9390 through 6.1.0.9397
Description The software contains a flaw due to improper neutralization of special elements used in an SQL command, leading to a SQL injection issue. This impacts the application's ability to securely interact with databases. The issue allows for Blind SQL Injection and SQL Injection. The vulnerability exists within Hibernate.
Recommendations Update PaperWork to version 6.1.0.9398 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10968

Affected Products

Hibernate
Paperwork