Junglewise Threat Intelligence

CVE-2025-41007: Cuantis SQL injection in search.php

CVE-2025-41007 · Severity: info · CVSS 9.3 · Published 2026-03-23

Executive brief

A critical security flaw has been identified in Cuantis, a sales management software. An attacker can exploit this vulnerability to gain unauthorized access to the underlying database, allowing them to view, modify, or delete sensitive business information. This could lead to a total loss of data integrity and confidentiality, potentially disrupting sales operations and exposing customer records.

Technical details

A SQL injection vulnerability exists in the '/search.php' endpoint of the Cuantis sales software. The flaw is located in the handling of the 'search' parameter, which fails to properly neutralize special elements used in SQL commands (CWE-89). An unauthenticated remote attacker can exploit this by sending specially crafted web requests to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary SQL queries, enabling them to retrieve, create, update, or delete data within the database. As of the advisory date, no official patch or solution has been reported.

Affected products

  • Cuantis Cuantis

Timeline

  • 2026-02-02: advisory: Initial advisory published by INCIBE-CERT
  • 2026-03-23: disclosed: CVE published to NVD

References