CVE-2025-13168 is a critical SQL injection vulnerability affecting ury-erp ury versions up to 0.2.0, specifically within the overrided_past_order_list function in the pos_extend.py file. This flaw allows for remote exploitation due to improper handling of the 'search_term' argument. With a CVSS score of 9.8 (CRITICAL), successful exploitation can lead to complete compromise of confidentiality, integrity, and availability. While public exploit code is available and the vendor has released a patch (version 0.2.1), there is currently no evidence of active exploitation, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.1CPE matchmatch criteria | cpe:2.3:a:ury:ury:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.