Skip to main content

CVE-2025-7919: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Simopro Technology WinMatrix3 Web package

High
VulnerabilityCVE-2025-7919cvecve-2025-7919cwe-200
Published: Mon Jul 21 2025 (07/21/2025, 06:16:00 UTC)
Source: CVE Database V5
Vendor/Project: Simopro Technology
Product: WinMatrix3 Web package

Description

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Technical Details

Data Version
5.1
Assigner Short Name
twcert
Date Reserved
2025-07-21T01:58:26.646Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 687ddeaaa83201eaac09d0af

Added to database: 7/21/2025, 6:31:06 AM

Last updated: 7/21/2025, 6:31:06 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats