CVE-2025-29980 describes a critical SQL injection vulnerability in eTRAKiT.net release 3.2.1.77, allowing unauthenticated remote attackers to execute arbitrary commands as the MS SQL server account due to improper input validation. With a CVSS score of 9.8, this flaw presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vendor recommends disabling the CRM feature and migrating to CentralSquare Community Development as eTRAKiT.net is no longer supported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.1.77CPE matchmatch criteria | cpe:2.3:a:centralsquare:etrakit.net:3.2.1.77:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.