216.73.217.22

CVE-2025-61548

· Published 08/01/2026 17:15 · Modified 08/01/2026 20:15

Labels: CVE-2025-61548 2026-01-08CVE-2025-61548CWE-89[email protected]

Essential information

Published
08/01/2026 17:15
Modified
08/01/2026 20:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
edu business solutions / print shop pro webdesk cpe:2.3:a:edu_business_solutions:print_shop_pro_webdesk:18.34:*:*:*:*:*:*:*

References