CVE-2025-56385
CRITICALWellSky Harmony 4.1.0.2.83 - SQL Injection via TXTUSERID Parameter in xmHarmony.asp
Title source: llmDescription
A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful authentication may lead to authentication bypass, data leakage, or full system compromise of backend database contents.
References (3)
Core 3
Core References
Broken Link
http://harmony.com
Product
http://wellsky.com
Third Party Advisory
https://machevalia.blog/blog/cve-2025-56385-wellsky-harmony-sql-injection
Scores
CVSS v3
9.8
EPSS
0.0044
EPSS Percentile
34.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
wellsky/harmony
4.1.0.2.83
Published
Nov 12, 2025
Tracked Since
Feb 18, 2026