CVE-2025-61548

Source
https://cve.org/CVERecord?id=CVE-2025-61548
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61548.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-61548
Published
2026-01-08T17:15:48.727Z
Modified
2026-03-14T12:45:25.345268Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61548.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "18.34"
            }
        ]
    }
]