CVE-2025-63689
Last modified
CVE-2025-63689 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ycf1998 | Money-Pos | < 2025-09-14 |
References
- https://gist.github.com/LockeTom/2ed0f3751c88542f48b7c230468d2a46Exploit, Third Party Advisory
- https://github.com/ycf1998/money-pos/issues/3Exploit, Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-63689?
How severe is CVE-2025-63689?
How do I fix CVE-2025-63689?
Are you affected by CVE-2025-63689?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
