CVE-2025-25763: SQL Injection
Published Mar 6, 2025
·Updated
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
Affected Software
2 affected components
crmeb CRMEB-KY<=v5.4.0
crmeb crmeb=5.4.0
Event History
Mar 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25763?
CVE-2025-25763 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2025-25763?
To fix CVE-2025-25763, upgrade CRMEB-KY to version v5.4.1 or higher.
3
What versions of CRMEB-KY are affected by CVE-2025-25763?
CRMEB-KY versions v5.4.0 and earlier are affected by CVE-2025-25763.
4
Where is the CVE-2025-25763 vulnerability located in the software?
The CVE-2025-25763 vulnerability is located in the getRead() function in /system/SystemDatabackupServices.php.
5
What type of vulnerability is CVE-2025-25763?
CVE-2025-25763 is a SQL Injection vulnerability.