No CVSS.
etSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files from disk, resulting in arbitrary local file disclosure.
No configuration.
15 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-12-15 15:15
Updated : 2025-12-15 19:16
NVD link : CVE-2025-34179
Mitre link : CVE-2025-34179
CVE.ORG link : CVE-2025-34179
JSON object : View
No product.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')