go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Netvision ISOinsight - SQL Injection

TVN ID TVN-202505011
CVE ID CVE-2025-4559
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ISOinsight v2.9.0.x, v3.0.0.x
Description The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution For v2.9.0.x, please update to version 2.9.0.250501 or later
For v3.0.0.x, please update to version 3.0.0.250501 or later
Credit Security member
Public Date 2025-05-12
Top