VYPR

Harmony

by Wellsky

CVEs (1)

  • CVE-2025-56385CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful…