CVE-2025-3707

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/05/2025
Last modified:
07/05/2025

Description

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun.net:ehrd_ctms:*:*:*:*:*:*:*:* 10.13 (including)