CVE-2025-29980
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 89
Summary
CVE-2025-29980: A critical SQL injection vulnerability has been identified in the eTRAKiT.net release 3.2.1.77. This issue arises due to insufficient input validation, allowing unauthenticated attackers to execute arbitrary commands using the MS SQL server account. Until a patch is released, it is strongly advised to disable the CRM feature in eTRAKiT.net. Note that eTRAKiT.Net is no longer supported, and users are encouraged to migrate to the latest version of CentralSquare Community Development to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.