CVE-2025-29980 Details
Description
A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no longer supported, and users are recommended to migrate to the latest version of CentralSquare Community Development.
A SQL injection vulnerability has been identified in CentralSquare eTRAKiT.Net version 3.2.1.77. This issue arises from inadequate input validation, allowing remote, unauthenticated attackers to execute arbitrary SQL commands and potentially arbitrary operating system commands as the current Microsoft SQL Server account. It is advised to disable the CRM feature while using eTRAKiT.Net version 3.2.1.77, as this version is no longer supported. Users are encouraged to upgrade to the latest version of CentralSquare Community Development.
eTRAKiT.Net is no longer supported. Users should upgrade to the latest version of CentralSquare Community Development.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2025CISA-ADP
Assessed Mar 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/pull/182/files#diff-53861466371a59578b21f5e4b4b6be7b2a6267c5d0fe81eda2a849bf6915ed8d | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Patch |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-079-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| centralsquare etrakit.net | 3.2.1.77 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2025 | Initial Analysis | [email protected] |
| Mar 20, 2025 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Mar 20, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |