CVE-2025-1158

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Feb 10, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-1158 is a critical vulnerability affecting ESAFENET CDG 5.6.3.154.205_20250114. The issue lies in an unknown function of the file addPolicyToSafetyGroup.jsp, where manipulation of the argument safetyGroupId allows for sql injection attacks. These assaults can be launched remotely, and the exploit has been publicly disclosed, increasing the risk for potential misuse. Despite early notification, the vendor has yet to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share