CVE-2025-67066

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

  • Published Sep 4, 2026
  • CVSS 9.8 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2025-67066 at the National Vulnerability Database