CVE-2025-63689 describes multiple critical SQL injection vulnerabilities in the ycf1998 money-pos system, specifically in versions prior to commit 11f276bd20a41f089298d804e43cb1c39d041e59. These flaws allow an unauthenticated remote attacker to execute arbitrary code by manipulating the 'orderby' parameter. With a CVSS score of 10.0 (Critical), the vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025-09-14CPE matchmatch criteria | cpe:2.3:a:ycf1998:money-pos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.