SQL Injection Vulnerability in BEIMS Contractor Web by FMI Works
CVE-2025-10460
What is CVE-2025-10460?
The vulnerability present in BEIMS Contractor Web arises from a SQL Injection flaw on the /BEIMSWeb/contractor.asp endpoint, which allows unauthorized users to access sensitive database information. Due to inadequate input validation through unsanitized parameter input, attackers can execute arbitrary SQL commands if this endpoint is accessible via the internet. This poses a significant risk to the database's confidentiality, integrity, and availability. As BEIMS Contractor Web is a legacy product that no longer receives maintenance or security patches from FMI Works, users are encouraged to assume that all versions, including those unverified, may be vulnerable until further vendor guidance is provided.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contractor Web 5.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
