First published: Tue Jan 28 2025(Updated: )
A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0789 is classified as a critical vulnerability.
CVE-2025-0789 is a SQL injection vulnerability affecting ESAFENET CDG V5.
CVE-2025-0789 can be exploited remotely by manipulating the argument 'flowId' in the /doneDetail.jsp file.
To fix CVE-2025-0789, it is recommended to sanitize and validate user inputs in the affected system.
There is currently no reported information on active exploitation of CVE-2025-0789, but caution is advised.