CVE-2025-48891

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
11/07/2025
Last modified:
11/07/2025

Description

A vulnerability exists in Advantech iView that could allow for SQL <br /> injection through the CUtils.checkSQLInjection() function. This <br /> vulnerability can be exploited by an authenticated attacker with at <br /> least user-level privileges, potentially leading to information <br /> disclosure or a denial-of-service condition.