Back to overview

CVE-2025-14598

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

Metadata

CVE ID
CVE-2025-14598
State
PUBLISHED
Assigner
certcc
Reserved
2025-12-12 17:31 UTC
Published
2026-01-09 12:14 UTC
Last updated
2026-01-09 15:52 UTC
Primary CWE
CWE-89
CWE-89 Improper Neutralization of Special Elements used in a…
Vendor / Product
BeeS Software Solutions / BET ePortal
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
BeeS Software Solutions BET ePortal 0 < ePortal : Secure Build (October 2025)
Weakness (CWE)
CWESourceDescription
cna CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 adp CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview