CVE-2025-12865: e-Excellence|U-Office Force - SQL Injection
Published Nov 10, 2025
·Updated
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
2 affected components
e-Excellence U-Office Force
Edetw U-office Force<29.50
Remediation
Information
Update to version 29.50 or later.
Event History
Nov 10, 2025
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12865?
CVE-2025-12865 is considered a high severity vulnerability due to its potential impact on database integrity.
2
How do I fix CVE-2025-12865?
To fix CVE-2025-12865, ensure that input validation and prepared statements are implemented to prevent SQL injection.
3
Who is affected by CVE-2025-12865?
CVE-2025-12865 affects users of the e-Excellence U-Office Force application.
4
What types of attacks can occur due to CVE-2025-12865?
Exploiting CVE-2025-12865 can allow attackers to read, modify, or delete sensitive database information.
5
Is CVE-2025-12865 an authenticated vulnerability?
Yes, CVE-2025-12865 requires authentication for an attacker to exploit the SQL injection vulnerability.