CVE-2025-12864: e-Excellence|U-Office Force - SQL Injection
Published Nov 10, 2025
·Updated
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
2 affected components
e-Excellence U-Office Force
Edetw U-office Force<29.50
Remediation
Information
Update to version 29.50 or later
Event History
Nov 10, 2025
CVE Published
via MITRE·02:15 AM
Data Sourced
via MITRE·02:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12864?
CVE-2025-12864 has a high severity level due to its potential for allowing unauthorized access to database contents.
2
How do I fix CVE-2025-12864?
To fix CVE-2025-12864, you should apply the latest patches provided by e-Excellence for the U-Office Force application.
3
Who is affected by CVE-2025-12864?
CVE-2025-12864 affects users of e-Excellence U-Office Force who have not implemented mitigation measures against SQL Injection vulnerabilities.
4
What type of vulnerability is CVE-2025-12864?
CVE-2025-12864 is classified as a SQL Injection vulnerability.
5
Can CVE-2025-12864 lead to data breaches?
Yes, CVE-2025-12864 can lead to data breaches by allowing attackers to read, modify, and delete database contents.