CVE-2025-61548 is a critical SQL Injection vulnerability affecting edu Business Solutions Print Shop Pro WebDesk version 18.34, specifically in the hfInventoryDistFormID parameter of the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint. This flaw, rated 9.8 CVSS (Critical), allows unauthenticated remote attackers to execute arbitrary SQL commands due to unsanitized user input. While there is no known public exploit code or active exploitation (KEV/Hot List inactive), the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.34CPE matchmatch criteria | cpe:2.3:a:edubusinesssolutions:print_shop_pro_webdesk:18.34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.