Vulnerability Description
A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful authentication may lead to authentication bypass, data leakage, or full system compromise of backend database contents.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wellsky | Harmony | 4.1.0.2.83 |
Related Weaknesses (CWE)
References
- http://harmony.comBroken Link
- http://wellsky.comProduct
- https://machevalia.blog/blog/cve-2025-56385-wellsky-harmony-sql-injectionThird Party Advisory
FAQ
What is CVE-2025-56385?
CVE-2025-56385 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not prope...
How severe is CVE-2025-56385?
CVE-2025-56385 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-56385?
Check the references section above for vendor advisories and patch information. Affected products include: Wellsky Harmony.