PT-2025-45420 · Hibernate+1 · Hibernate+1

·

CVE-2025-10968

·

Published

2025-11-07

·

Updated

2026-06-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaperWork versions 6.1.0.9390 through 6.1.0.9397
Description The software contains a flaw due to improper neutralization of special elements used in an SQL command, leading to a SQL injection issue. This impacts the application's ability to securely interact with databases. The issue allows for Blind SQL Injection and SQL Injection. The vulnerability exists within Hibernate.
Recommendations Update PaperWork to version 6.1.0.9398 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10968

Affected Products

Hibernate
Paperwork