Executive brief
A critical security vulnerability has been identified in Dolusoft Omaspot, a software service. This flaw allows unauthorized individuals to manipulate the underlying database by sending malicious commands. An attacker could exploit this to steal sensitive customer data, modify records, or disrupt the availability of the service entirely.
Technical details
Dolusoft Omaspot contains an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this to perform unauthorized data exfiltration, modification, or deletion within the database. The issue is resolved in versions released on or after September 12, 2025.
Affected products
- Dolusoft Omaspot before 12.09.2025
Timeline
- 2025-09-16: disclosed
- 2025-09-16: advisory
- 2025-09-12: patched