SQL Injection in SIMPLE.ERP
Published Oct 21, 2025
7.1
HIGHCVSS 4.0
EPSS 0.28%
Description
SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injection. Potential exploitation is limited by the 20-character limit in form fields. Identified use case allows to delete tables with a name of maximum 6 characters. We weren't able to identify a way to exfiltrate data within query character limit.
This issue affects SIMPLE.ERP in versions before 6.30@a04.3.
Affected products
-
- Version 0StatusaffectedConstraints<6.30@a04.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Simple SA | Simple.erp | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://cert.pl/en/posts/2025/10/CVE-2025-9339/ third-party-advisory
- https://simple.com.pl/ product
| Link | Providers | Tags |
|---|---|---|
| https://cert.pl/en/posts/2025/10/CVE-2025-9339/ | third-party-advisory | |
| https://simple.com.pl/ | product |
Change history (0)
No recorded changes yet.