CVE-2025-9339 is a SQL injection vulnerability in the warehouse document filtering form of SIMPLE.ERP software versions prior to [email protected]. A logged-in user can inject malicious SQL queries, but exploitation is limited by a 20-character field limit, preventing data exfiltration but allowing table deletion for tables with names up to 6 characters. This vulnerability has a CVSSv4 score of 7.1 (High), indicating a network-based attack with low privileges required and high impact on availability. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Simple SA | SIMPLE.ERP |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.