PT-2025-43604 · Basis Technology · Netty Erp

·

CVE-2025-11253

·

Published

2025-10-24

·

Updated

2026-06-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aksis Technology Inc. Netty ERP versions prior to V.1.1000
Description Netty ERP contains a flaw due to improper neutralization of special elements used in an SQL command, leading to a SQL Injection issue. This allows for the potential execution of arbitrary SQL commands. The issue does not require login, potentially allowing unauthenticated attackers to compromise the system. The vulnerability could lead to data theft or system compromise.
Recommendations Versions prior to V.1.1000 should be updated to V.1.1000 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11253

Affected Products

Netty Erp