CVE-2025-24612
CVSS 3.1 Score 9.3 of 10 (high)
Details
Summary
CVE-2025-24612 is a newly identified SQL Injection vulnerability affecting MORKVA Shipping for Nova Poshta from version n/a through 1.19.6. Maliciously crafted SQL commands can be injected into the application, potentially granting unauthorized access to sensitive data or allowing attackers to modify or delete information. This issue occurs due to improper neutralization of special elements used in SQL commands. SQL Injection vulnerabilities are a significant risk, as they can lead to data breaches and system compromise. It is strongly recommended that users of the affected version of MORKVA Shipping for Nova Poshta upgrade to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.