First published: Tue Jan 28 2025(Updated: )
A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0786 has been classified as a critical vulnerability.
CVE-2025-0786 affects an unknown function of the /appDetail.jsp file in ESAFENET CDG, allowing for SQL injection.
Yes, CVE-2025-0786 can be exploited remotely.
CVE-2025-0786 is associated with SQL injection attacks due to the manipulation of the argument flowId.
Exploiting CVE-2025-0786 could allow attackers to gain unauthorized access to the database and manipulate its contents.