SQL Injection Vulnerability in ControlID iDSecure On-Premises Software
CVE-2025-49853
9.3CRITICAL
What is CVE-2025-49853?
ControlID's iDSecure On-premises software, specifically versions up to and including 4.7.48.0, is susceptible to SQL injection attacks. This vulnerability enables unauthorized users to manipulate SQL queries, leading to potential data leakage and unauthorized access to confidential information. Attackers can exploit this weakness to execute arbitrary SQL commands, resulting in severe security implications for affected systems.
Affected Version(s)
iDSecure On-premises 0 <= 4.7.48.0