CVE-2025-41019: Sergestec Sistick
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'id' parameter in '/index.php?view=ticket_detail'.
Affected products
- Sergestec Sistick: version 7.2 only
Published 2025-10-16. Last modified 2026-10-08.