CVE-2025-56385
Critical · CVSS 9.8WellSky Harmony — SQL Injection Authentication Bypass
- CVSS
- 9.8
- nvd
- EPSS
- 0.40%
- 32th pct
- KEV
- No
- Class
- other
- CWE-89
Description
A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful authentication may lead to authentication bypass, data leakage, or full system compromise of backend database contents.
Search profile — drives PoC discovery
Symbols xmHarmony.aspTXTUSERID
Keywords CVE-2025-56385WellSky HarmonySQL injectionxmHarmony.aspTXTUSERIDauthentication bypassWellSky Harmony 4.1.0.2.83
Versions: 4.1.0.2.83
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z