CVE-2025-67066
9.8Oasys · Sysoa
A SQL injection vulnerability in Sysoa version 1.0 allows a remote, unauthenticated attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path.
Executive summary
A critical SQL injection vulnerability in Sysoa version 1.0 enables remote, unauthenticated attackers to achieve arbitrary code execution.
Vulnerability
The application is vulnerable to SQL injection via the outtype parameter within the /outaddresspaging path. This flaw allows an unauthenticated remote attacker to interact with the backend database and execute arbitrary code.
Business impact
This vulnerability is critical, carrying a CVSS score of 9.8. Successful exploitation grants an attacker full control over the application and underlying data, which could lead to complete system compromise, data theft, and total loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Identify and disable the affected functionality if an official patch is not yet available, or contact the vendor for immediate remediation guidance.
Proactive Monitoring: Review database query logs for suspicious patterns, such as unexpected SQL syntax or unauthorized access attempts originating from the /outaddresspaging endpoint.
Compensating Controls: Implement strict input validation and sanitization at the Web Application Firewall (WAF) level to block common SQL injection payloads targeting the outtype parameter.
Exploitation status
Public Exploit Available: Yes (a published PoC exists, attributed to the referenced GitHub write-up)
Analyst recommendation
This is an extremely severe vulnerability that requires immediate attention. If this software is in use, it must be isolated from the network until a patch is applied, as public exploitation material is available and the risk of compromise is critical.
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written
- Analyst report updated
- Published in the daily brief critical section, early-warning entry