CVE-2025-67066: SQL Injection
Published Sep 4, 2026
·Updated
SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
Affected Software
1 affected component
Oasys sysoa=1.0
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which systems should be prioritized for remediation?
Prioritize Oasys sysoa version 1.0 deployments, particularly where the /outaddresspaging path is remotely reachable.
2
What does an attacker need to exploit this issue?
A remote attacker needs to send a request that supplies a malicious value through the outtype parameter on the /outaddresspaging path. Successful exploitation can allow arbitrary code execution.