CVE-2025-14598
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| BeeS Software Solutions | BET ePortal | — | 0 < ePortal : Secure Build (October 2025) |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CWE-89 | adp | CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | adp | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (3)