


Perceptive Security
SOC/SIEM Consultancy

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in th…
Published:
25 maart 2026 om 23:00:00
Alert date:
26 maart 2026 om 13:04:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Enterprise Applications
CVE-2018-25202 affects SAT CFDI 3.3, a tax compliance system, containing a critical SQL injection vulnerability in the signIn endpoint. Attackers can exploit the 'id' parameter through POST requests using boolean-based blind, stacked queries, or time-based blind SQL injection techniques. This vulnerability allows manipulation of database queries to extract sensitive data or compromise the application. Multiple proof-of-concept exploits are available, indicating active threat potential. The vulnerability represents a significant risk to organizations using this tax compliance system.
Technical details
Mitigation steps:
Affected products:
SAT CFDI 3.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25202
https://www.exploit-db.com/exploits/44726
https://www.vulncheck.com/advisories/sat-cfdi-sql-injection-via-signin-endpoint
https://www.wecodex.com/item/view/verification-and-validation-system-sat-cfdi-33/8
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
