CVE-2025-41028
20.10.2025, 09:15
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter sEstadoUsr in /epsilonnetws/WSAvisos.asmx.
Awaiting analysis
This vulnerability is currently awaiting analysis.