CVE-2025-0603 PUBLISHED

SQLi in Callvision Healthcare's Callvision Emergency Code

Assigner: TR-CERT
Reserved: 20.01.2025 Published: 07.10.2025 Updated: 07.10.2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection.This issue affects Callvision Emergency Code: before V3.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Callvision Healthcare
Product Callvision Emergency Code
Versions Default: unaffected
  • affected from 0 to V3.0 (excl.)

Credits

  • Mustafa GÜNEL finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection
  • CAPEC-7 Blind SQL Injection