CVE-2025-31619

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 89

Summary

CVE-2025-31619 is an SQL Injection vulnerability affecting marcoingraiti Actionwear products sync. The issue arises from improper neutralization of special elements in SQL commands, enabling attackers to inject malicious queries and potentially gain unauthorized access to sensitive data or modify database information. This vulnerability affects Actionwear products sync versions from n/a through 2.3.3. Successful exploitation could lead to serious consequences, including data theft or system compromise. It is recommended that users upgrade to the latest version of the product to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share