CVE-2025-7919
BaseFortify
Publication date: 2025-07-21
Last updated on: 2025-07-22
Assigner: TWCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| simopro_technology | winmatrix3 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a SQL Injection in the WinMatrix3 Web package developed by Simopro Technology. It allows unauthenticated remote attackers to inject arbitrary SQL commands into the database, which can lead to unauthorized reading, modification, and deletion of database contents.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized access to sensitive data, potential data loss or corruption, and disruption of database integrity. Attackers can read, modify, or delete database contents without authentication, which can compromise the security and availability of the affected system.