CVE-2025-41007
Last modified
CVE-2025-41007 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in the '/search.php' endpoint.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in the '/search.php' endpoint.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-41007?
How severe is CVE-2025-41007?
How do I fix CVE-2025-41007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41001Cross Site Scripting (XSS) vulnerability stored in SOPlannin…5.4
- CVE-2025-41002SQL injection vulnerability in Infoticketing. This vulnerabi…9.3
- CVE-2025-41003Imaster's Patient Record Management System contains a stored…5.1
- CVE-2025-41004Imaster's Patient Records Management System is vulnerable to…8.7
- CVE-2025-41005Imaster's MEMS Events CRM contains an SQL injection vulnerab…8.7
- CVE-2025-41006Imaster's MEMS Events CRM contains an SQL injection vulnerab…9.3
- CVE-2025-41008SQL injection vulnerability in Sinturno. This vulnerability …9.3
- CVE-2025-41009SQL injection vulnerability in the DRED virtual campus platf…9.3
- CVE-2025-4101The MultiVendorX – WooCommerce Multivendor Marketplace Solut…4.3
- CVE-2025-41010Incorrect Cross-Origin Resource Sharing (CORS) configuration…5.1
- CVE-2025-41011HTML injection vulnerability in PHP Point of Sale v19.4. Thi…6.1
- CVE-2025-41012Unauthorized access vulnerability in TCMAN GIM v11 version 2…5.3
Are you affected by CVE-2025-41007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
