go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

PiExtract SOOP-CLM - SQL Injection

TVN ID TVN-202503005
CVE ID CVE-2025-3011
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SOOP-CLM from version v5.1.0 to 5.3.0
Description SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Update to version v5.3.1 or later
Credit xiaoswaii
Public Date 2025-03-31
Top