An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.
References
Configurations
No configuration.
History
31 Oct 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter. |
30 Oct 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/zsamamah/CVE-2025-61196/blob/main/CVE-2025-61196.md - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-94 |
30 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 17:15
Updated : 2025-10-31 15:15
NVD link : CVE-2025-61196
Mitre link : CVE-2025-61196
CVE.ORG link : CVE-2025-61196
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
