CVE-2025-40985

HIGH

SCATI Vision Web <7.2 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the ‘login’ parameter in the endpoint ‘/scatevision_web/index.php/loginForm’.

References (1)

Core 1

Scores

CVSS v4 8.3
EPSS 0.0033
EPSS Percentile 24.6%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
SCATI/SCATI Vision Web 4.8 - 7.2
Published Jul 16, 2025
Tracked Since Feb 18, 2026