ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Assaabloy
Assaabloy control Id Idsecure |
|
CPEs | cpe:2.3:a:assaabloy:control_id_idsecure:*:*:*:*:on-premises:*:*:* | |
Vendors & Products |
Assaabloy
Assaabloy control Id Idsecure |
Fri, 27 Jun 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 24 Jun 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries. | |
Title | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in ControlID iDSecure On-premises | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-06-24T19:23:19.181Z
Updated: 2025-06-27T17:13:55.451Z
Reserved: 2025-06-11T15:48:15.494Z
Link: CVE-2025-49853

Updated: 2025-06-24T19:43:24.351Z

Status : Analyzed
Published: 2025-06-24T20:15:25.873
Modified: 2025-07-02T16:32:40.317
Link: CVE-2025-49853

No data.