CVE-2025-7343: Digiwin|SFT - SQL Injection
The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Digiwin SFTto a version that resolves this vulnerability.Fixed in 3.7.4.5 - Upgrade
Upgrade
Digiwin SFTto a version that resolves this vulnerability.Patch KB202505001
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7343?
CVE-2025-7343 is considered a high-severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2025-7343?
To mitigate CVE-2025-7343, it is recommended to sanitize user inputs and implement parameterized queries in the application.
Who is affected by CVE-2025-7343?
CVE-2025-7343 affects users of the Digiwin SFT software, allowing for SQL injection attacks.
What can attackers do using CVE-2025-7343?
Attackers exploiting CVE-2025-7343 can execute arbitrary SQL commands, potentially leading to data theft or manipulation.
Is authentication required to exploit CVE-2025-7343?
No, CVE-2025-7343 can be exploited by unauthenticated remote attackers, increasing its risk.