CVE-2025-22214

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 89

Summary

CVE-2025-22214 is a vulnerability affecting Landray EIS 2001 to 2006. This issue permits SQL injection attacks on Message/fi_message_receiver.aspx?replyid=. An attacker can exploit this vulnerability by manipulating the input of the 'replyid' parameter, potentially gaining unauthorized access to sensitive data or executing malicious commands on the affected system. This vulnerability poses a serious threat to security and requires immediate patching or mitigation efforts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share