CVE-2025-24667

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Jan 27, 2025
CWE ID 89

Summary

CVE-2025-24667 is a newly disclosed SQL Injection vulnerability affecting Eniture Technology's Small Package Quotes – Worldwide Express Edition. The issue arises from improper neutralization of special elements in SQL commands, permitting an attacker to inject malicious SQL statements. This vulnerability, present in versions from n/a to 5.2.17, could potentially allow unauthorized access or data modification within the affected system. SQL Injection attacks can lead to severe consequences, including data breaches or system compromises, making it essential for users to promptly apply the necessary patches or upgrades to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share