Back to search
CVE-2025-40985
Published: Jul 16, 2025
Modified: Jul 16, 2025
PUBLISHED
Description
SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the ‘login’ parameter in the endpoint ‘/scatevision_web/index.php/loginForm’.
| Vendor | Product | Versions |
|---|---|---|
SCATI | SCATI Vision Web | affected 4.8 - <= 7.2 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now