CVE-2025-2927
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 28, 2025
Updated: Apr 14, 2025
CWE ID 89
CWE ID 74
Summary
CVE-2025-2927 is a newly disclosed critical vulnerability affecting ESAFENET CDG 5.6.3.154.205. This issue lies within an unknown function of the file /parameter/getFileTypeList.jsp. The vulnerability is characterized by sql injection, which can be triggered by manipulating the typename argument. An attacker can exploit this remotely, making it a significant threat. Unfortunately, the exploit has been made public, increasing the risk of potential attacks. Despite early disclosure to the vendor, they have yet to respond or provide a patch.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- EsafeNet