SQL Injection Vulnerability in ControlID iDSecure On-Premises Software
CVE-2025-49853

9.3CRITICAL

Key Information:

Vendor

Controlid

Vendor
CVE Published:
24 June 2025

What is CVE-2025-49853?

ControlID's iDSecure On-premises software, specifically versions up to and including 4.7.48.0, is susceptible to SQL injection attacks. This vulnerability enables unauthorized users to manipulate SQL queries, leading to potential data leakage and unauthorized access to confidential information. Attackers can exploit this weakness to execute arbitrary SQL commands, resulting in severe security implications for affected systems.

Affected Version(s)

iDSecure On-premises 0 <= 4.7.48.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noam Moshe of Claroty Team82
.
CVE-2025-49853 : SQL Injection Vulnerability in ControlID iDSecure On-Premises Software