CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-56385

Critical · CVSS 9.8

WellSky Harmony — SQL Injection Authentication Bypass

CVSS
9.8
nvd
EPSS
0.40%
32th pct
KEV
No
Class
other
CWE-89

Description

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful authentication may lead to authentication bypass, data leakage, or full system compromise of backend database contents.

Search profile — drives PoC discovery

Symbols xmHarmony.aspTXTUSERID
Keywords CVE-2025-56385WellSky HarmonySQL injectionxmHarmony.aspTXTUSERIDauthentication bypassWellSky Harmony 4.1.0.2.83
Versions: 4.1.0.2.83

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z