CVE-2025-1158
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Feb 10, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-1158 is a critical vulnerability affecting ESAFENET CDG 5.6.3.154.205_20250114. The issue lies in an unknown function of the file addPolicyToSafetyGroup.jsp, where manipulation of the argument safetyGroupId allows for sql injection attacks. These assaults can be launched remotely, and the exploit has been publicly disclosed, increasing the risk for potential misuse. Despite early notification, the vendor has yet to respond to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- EsafeNet