SQL Injection Vulnerability in Sergestec's SISTICK Product
CVE-2025-41019

9.3CRITICAL

Key Information:

Vendor

Sergestec

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-41019?

Sergestec's SISTICK version 7.2 is susceptible to SQL injection, which allows malicious users to manipulate SQL queries via the 'id' parameter in the 'index.php?view=ticket_detail' endpoint. This vulnerability could enable attackers to gain unauthorized access to databases, allowing them to retrieve, create, update, or delete critical data, thereby compromising the integrity and confidentiality of the information stored.

Affected Version(s)

SISTICK 7.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ignacio Aldarabi
.
CVE-2025-41019 : SQL Injection Vulnerability in Sergestec's SISTICK Product