SQL Injection Vulnerability in GG Soft Software Services Inc. PaperWork Application
CVE-2025-10968

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-10968?

A SQL Injection vulnerability in the PaperWork application by GG Soft Software Services Inc. allows attackers to execute arbitrary SQL commands through crafted input. This vulnerability can lead to unauthorized access to sensitive data, data corruption, and other malicious activities. Users running versions 6.1.0.9390 to previous 6.1.0.9398 are at risk and should upgrade immediately to enhance security.

Affected Version(s)

PaperWork 6.1.0.9390 < 6.1.0.9398

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Murat ERDEMİR
.
CVE-2025-10968 : SQL Injection Vulnerability in GG Soft Software Services Inc. PaperWork Application