9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter โsEstadoUsrโ in โ/epsilonnetws/WSAvisos.asmxโ.
Basic Information
ID
CVE-2025-41028
Source
INCIBE
Published
Oct 20, 2025 at 09:00
Affected Product
Vendor
Grupo Castilla
Product
Epsilon RH
Version
3.03.36.0121
Affected Versions
Grupo Castilla Epsilon RH 3.03.36.0121