Cyber Posture

CVE-2025-29980

Critical

Published: 20 March 2025

Published
20 March 2025
Modified
23 September 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0052 66.8th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-29980 is a SQL injection vulnerability (CWE-89) in eTRAKiT.net release 3.2.1.77, stemming from improper input validation. This flaw affects the eTRAKiT.net software, which has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity with high impacts on confidentiality, integrity, and availability.

A remote unauthenticated attacker can exploit the vulnerability over the network with low complexity and no user interaction required. Successful exploitation allows the attacker to execute arbitrary commands as the current Microsoft SQL Server account.

Advisories recommend turning off the CRM feature while using eTRAKiT.net release 3.2.1.77 as a mitigation. eTRAKiT.Net is no longer supported, and users are advised to migrate to the latest version of CentralSquare Community Development.

Details

CWE(s)
CWE-89

Affected Products

centralsquare
etrakit.net
3.2.1.77

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

SQL injection in public-facing web application (eTRAKiT.net) allows remote unauthenticated arbitrary command execution, directly enabling T1190 Exploit Public-Facing Application.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References