Junglewise Threat Intelligence

CVE-2025-4738: Yirmibes Software MY ERP SQL injection

CVE-2025-4738 · Severity: critical · CVSS 9.8 · Published 2025-06-19

Executive brief

A critical security vulnerability has been identified in Yirmibes Software MY ERP, an enterprise resource planning system used to manage business processes and data. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive corporate information, data modification, or a complete system shutdown. This issue can be exploited remotely without requiring any user interaction or login credentials.

Technical details

A SQL injection vulnerability (CWE-89) exists in Yirmibes Software MY ERP due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Successful exploitation can lead to full disclosure of database contents, unauthorized modification of data, or denial-of-service conditions. The vulnerability is addressed in version 1.170.

Affected products

  • Yirmibes Software MY ERP before 1.170

Timeline

  • 2025-06-19: advisory: Initial disclosure by TR-CERT/USOM
  • 2025-06-19: disclosed

References