CVE 9.3 CRITICAL

SQL injection in Epsilon RH_CVE-2025-41028

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter โ€˜sEstadoUsrโ€™ in โ€˜/epsilonnetws/WSAvisos.asmxโ€™.

Basic Information

ID CVE-2025-41028
Source INCIBE
Published Oct 20, 2025 at 09:00

Affected Product

Vendor Grupo Castilla
Product Epsilon RH
Version 3.03.36.0121
Affected Versions Grupo Castilla Epsilon RH 3.03.36.0121

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.