CVE ID | CVE-2025-9339 |
Publication date | 21 October 2025 |
Vendor | Simple SA |
Product | SIMPLE.ERP |
Vulnerable versions | All before [email protected] |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in SIMPLE.ERP software and participated in coordination of its disclosure.
The vulnerability CVE-2025-9339: SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user to send a payload of up to 20 characters. Identified use case allows to delete tables with a name of maximum 6 characters. We weren't able to identify a way to exfiltrate data within query character limit.
This issue affects SIMPLE.ERP in versions before [email protected].
Credits
We thank Kamil Dąbkowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.