Vulnerability in E4 Sistemas Mercatus ERP allows resource manipulation
CVE-2025-9619

6.9MEDIUM

Key Information:

Vendor
CVE Published:
29 August 2025

What is CVE-2025-9619?

A significant security flaw exists in the E4 Sistemas Mercatus ERP version 2.00.019, specifically related to an unregulated function found within the /basico/webservice/imprimir-danfe/id/ path. This vulnerability enables attackers to manipulate resource identifiers, potentially allowing unauthorized access or control. Remote exploitation is a possibility, escalating the severity of the risk. Despite early notifications provided to the vendor, there has been no response regarding remediation.

Affected Version(s)

Mercatus ERP 2.00.019

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cadeolog (VulDB User)
.
CVE-2025-9619 : Vulnerability in E4 Sistemas Mercatus ERP allows resource manipulation