CVE-2025-65235: SQL Injection
Published Nov 26, 2025
·Updated
OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.
Affected Software
2 affected components
OpenCode Systems USSD Gateway OC
OpenCode USSD Gateway=6.13.11
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65235?
CVE-2025-65235 is classified as a moderate severity SQL injection vulnerability.
2
How do I fix CVE-2025-65235?
To fix CVE-2025-65235, sanitize and validate the ID parameter in the getSubUsersByProvider function to prevent SQL injection.
3
What systems are affected by CVE-2025-65235?
CVE-2025-65235 affects OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11.
4
What type of vulnerability is CVE-2025-65235?
CVE-2025-65235 is a SQL injection vulnerability.
5
What actions should be taken if CVE-2025-65235 is discovered in my system?
If CVE-2025-65235 is discovered, immediately implement the recommended fixes and conduct a security assessment of your system.