CVE-2025-13757: SQL Injection
Published Nov 27, 2025
·Updated
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.
Affected Software
3 affected components
Devolutions Server<=2025.3.8
Devolutions Devolutions Server<2025.2.21.0
Devolutions Devolutions Server>=2025.3.2.0<2025.3.10.0
Event History
Nov 27, 2025
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13757?
CVE-2025-13757 is classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2025-13757?
To fix CVE-2025-13757, upgrade Devolutions Server to version 2025.3.9 or later.
3
What is affected by CVE-2025-13757?
CVE-2025-13757 affects Devolutions Server versions up to and including 2025.3.8.
4
What type of vulnerability is CVE-2025-13757?
CVE-2025-13757 is an SQL Injection vulnerability that can allow unauthorized access to the database.
5
When was CVE-2025-13757 reported?
CVE-2025-13757 was reported as an issue affecting Devolutions Server before version 2025.3.8.