Executive brief
A security vulnerability exists in the E1 Informatics Web Application that could allow unauthorized individuals to interfere with the application's database. By exploiting this flaw, an attacker could potentially access sensitive customer data, modify records, or disrupt business operations. As of the latest report, the vendor has not confirmed a fix, posing a significant risk to organizations using this software.
Technical details
The E1 Informatics Web Application is vulnerable to SQL injection (CWE-89) due to improper neutralization of special elements used in SQL commands. This vulnerability can be exploited by a remote, unauthenticated attacker over the network without any user interaction. Successful exploitation allows the attacker to read sensitive data from the database, modify or delete data, and potentially gain administrative access to the application. At the time of disclosure, the vendor had not provided information regarding a patch or mitigation, and the vulnerability is confirmed to affect versions through 20250916.
Affected products
- E1 Informatics Web Application through 20250916
Timeline
- 2025-09-16: disclosed: Initial disclosure by USOM/TR-CERT
- 2025-09-16: advisory: CVE published to NVD