CVE-2025-41028EPSS p38.8%
CVE-2025-41028CVE-2025-41028
Description
A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to retrieve, create, update and delete database via sending a POST request using the parameter ‘sEstadoUsr’ in ‘/epsilonnetws/WSAvisos.asmx’.
Scoring
| EPSS | 0.47% probability of exploitation · percentile 38.8% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |