SQL Injection Vulnerability in Sergestec's SISTICK Product
CVE-2025-41019
9.3CRITICAL
What is CVE-2025-41019?
Sergestec's SISTICK version 7.2 is susceptible to SQL injection, which allows malicious users to manipulate SQL queries via the 'id' parameter in the 'index.php?view=ticket_detail' endpoint. This vulnerability could enable attackers to gain unauthorized access to databases, allowing them to retrieve, create, update, or delete critical data, thereby compromising the integrity and confidentiality of the information stored.
Affected Version(s)
SISTICK 7.2