Unrated severityNVD Advisory· Published Dec 8, 2025· Updated Dec 8, 2025
Galaxy Software Services|Vitals ESP - SQL Injection
CVE-2025-14254
Description
Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
Affected products
2- Galaxy Software Services/Vitals ESPv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.twcert.org.tw/en/cp-139-10543-380bd-2.htmlmitrethird-party-advisory
- www.twcert.org.tw/tw/cp-132-10542-4c682-1.htmlmitrethird-party-advisory
News mentions
0No linked articles in our index yet.