go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

HAMASTAR Technology WIMP website co-construction management platform - SQL Injection

TVN ID TVN-202506005
CVE ID CVE-2025-6169
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products WIMP version 5.3.1.34642 and earlier
Description The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Update to version 5.3.1.34643 or later
Credit 周大策 (Charlie Chou / CHOU TA CHE)(CHT Security)
Public Date 2025-06-16
Top