CVE-2025-3400

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-3400 is a recently disclosed critical vulnerability affecting ESAFENET CDG 5.6.3.154.205_20250114. The issue lies in the /client/UnChkMailApplication.jsp file, where a sql injection vulnerability can be triggered by manipulating the typename argument. This problem enables remote attackers to initiate the exploit, making it a significant security risk. The vulnerability details have been made public, and the lack of a response from the vendor raises concerns about potential unpatched systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share