SQL Injection Vulnerability in Deerwms Deer-WMS 2 by Deerwms
CVE-2025-8123
Key Information:
- Vendor
Deerwms
- Status
- Vendor
- CVE Published:
- 24 July 2025
Badges
What is CVE-2025-8123?
A SQL injection vulnerability has been identified in Deerwms Deer-WMS versions up to 3.3, specifically within an undocumented function located in the /system/dept/edit file. By manipulating the argument 'ancestors', an attacker could execute malicious SQL queries, leading to potential unauthorized access and data compromise. This vulnerability can be exploited remotely, making it a significant threat to users of affected versions. Publicly disclosed exploits may facilitate attacks, highlighting the need for immediate attention and mitigation measures.
Affected Version(s)
deer-wms-2 3.0
deer-wms-2 3.1
deer-wms-2 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved