go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Digiwin|SFT - SQL Injection

TVN ID TVN-202507013
CVE ID CVE-2025-7343
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products SFT version 3.7.12 and earlier
Description The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Update to version 3.7.4.5 or later, and install patch KB202505001
Credit AAA Security Technology
Public Date 2025-07-21
Top