First published: Fri May 02 2025(Updated: )
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Sunnet eHDR CTMS |
Contact the vendor to obtain the patch.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3707 has a high severity rating due to its potential to allow remote attackers to perform SQL injections.
To fix CVE-2025-3707, update the Sunnet eHDR CTMS to the latest version that patches this vulnerability.
CVE-2025-3707 can facilitate SQL injection attacks that enable unauthorized access to database contents.
CVE-2025-3707 affects users of the Sunnet eHDR CTMS software.
Yes, CVE-2025-3707 can be exploited remotely by attackers with regular user privileges.