CVE-2025-41028
EUVD-2025-3504320.10.2025, 09:15
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter ‘sEstadoUsr’ in ‘/epsilonnetws/WSAvisos.asmx’.
Awaiting analysis
This vulnerability is currently awaiting analysis.