Junglewise Threat Intelligence

CVE-2025-29267: Abis Adjutant Core Accounting ERP SQL injection in cid parameter

CVE-2025-29267 · Severity: medium · CVSS 6.5 · Published 2025-07-08

Executive brief

A security vulnerability exists in the Abis Adjutant Core Accounting ERP system, which is used for business resource planning and financial management. An attacker can exploit this flaw to gain unauthorized access to sensitive information stored in the company's database. This could lead to the exposure of private financial records, customer data, or internal business operations.

Technical details

An error-based SQL injection vulnerability exists in the 'cid' parameter of the Adjutant Core Accounting (ERP) software. The flaw is located in the /api/task endpoint and is caused by a lack of input sanitization when processing GET requests. An unauthenticated remote attacker can exploit this by sending specially crafted SQL payloads to extract information from the backend Microsoft SQL Server database. As of the advisory date, the vendor has reportedly not provided a fix despite notification in January 2025.

Affected products

  • Abis, Inc. Adjutant Core Accounting ERP v.PreBeta250F

Timeline

  • 2025-01: disclosed: Vulnerability discovered and vendor notified
  • 2025-07-08: advisory: CVE published to NVD

References