SQL Injection Vulnerability in Vitals ESP by Galaxy Software Services
CVE-2025-14254

7.1HIGH

Key Information:

Vendor
CVE Published:
8 December 2025

What is CVE-2025-14254?

The Vitals ESP application developed by Galaxy Software Services contains an SQL injection flaw. This vulnerability enables authenticated remote attackers to exploit the application by injecting arbitrary SQL commands. Such actions can lead to unauthorized access to sensitive database contents, posing significant risks to the integrity and confidentiality of the data stored within.

Affected Version(s)

Vitals ESP 0 <= 6.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-14254 : SQL Injection Vulnerability in Vitals ESP by Galaxy Software Services