CVE-2025-62575

NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
Configurations

No configuration.

History

02 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 21:15

Updated : 2025-12-04 17:15


NVD link : CVE-2025-62575

Mitre link : CVE-2025-62575

CVE.ORG link : CVE-2025-62575


JSON object : View

Products Affected

No product.

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource