Description
An Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) allowing SQL Injection in Dolusoft Omaspot. Affects versions before 12.09.2025. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
CVSS Vector
Primary assessmentCNA · 9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV: NetworkAC: LowPR: NoneUI: NoneS: UnchangedC: HighI: HighA: High
References
Record Verification
CreditThe official CVE record credits Sevban Donmez as finder
PublishedThe CVE record was published on 2025-09-16
CheckedMetadata last checked against the CVE Services record on 2026-08-23
