Junglewise Threat Intelligence

CVE-2025-7744: Dolusoft Omaspot SQL injection

CVE-2025-7744 · Severity: critical · CVSS 9.8 · Published 2025-09-16

Technologies: Dolusoft Omaspot. Vendors: Dolusoft.

Executive brief

A critical security vulnerability has been identified in Dolusoft Omaspot, a software service. This flaw allows unauthorized individuals to manipulate the underlying database by sending malicious commands. An attacker could exploit this to steal sensitive customer data, modify records, or disrupt the availability of the service entirely.

Technical details

Dolusoft Omaspot contains an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this to perform unauthorized data exfiltration, modification, or deletion within the database. The issue is resolved in versions released on or after September 12, 2025.

Affected products

  • Dolusoft Omaspot before 12.09.2025

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory
  • 2025-09-12: patched

References

Related threats