Junglewise Threat Intelligence

CVE-2025-10610: SFS Consulting Winsure SQL injection

CVE-2025-10610 · Severity: critical · CVSS 9.8 · Published 2025-10-14

Executive brief

Winsure, an insurance industry software solution, contains a critical security flaw that allows unauthorized individuals to access its underlying database. By exploiting this vulnerability, an attacker could steal sensitive customer information, modify business records, or disrupt the system's operations. This pose a significant risk to data privacy and business continuity for organizations using the affected versions.

Technical details

A Blind SQL Injection vulnerability (CWE-89) exists in SFS Consulting Winsure through the version dated 21.08.2025. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an unauthenticated attacker to send crafted queries over the network. Because it is a 'blind' injection, an attacker can infer data by observing differences in application responses or timing. Successful exploitation grants full access to the backend database, potentially leading to complete data exfiltration, unauthorized modification of records, or administrative bypass.

Affected products

  • SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure through Version dated 21.08.2025

Timeline

  • 2025-10-14: disclosed
  • 2025-10-14: advisory

References