The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-13291 The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
Fixes

Solution

Contact the vendor to obtain the patch.


Workaround

No workaround given by the vendor.

History

Wed, 07 May 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Sun.net
Sun.net ehrd Ctms
CPEs cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:*
Vendors & Products Sun.net
Sun.net ehrd Ctms

Fri, 02 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 May 2025 03:30:00 +0000

Type Values Removed Values Added
Description The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
Title Sunnet eHRD CTMS - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-05-02T16:28:39.998Z

Reserved: 2025-04-16T07:44:36.577Z

Link: CVE-2025-3707

cve-icon Vulnrichment

Updated: 2025-05-02T16:28:33.878Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-02T04:15:55.140

Modified: 2025-05-07T16:50:32.967

Link: CVE-2025-3707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.