S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 12, 2026

CVE-2025-22214 Scanner

Targets the document management module's input parameter, allowing attackers to execute arbitrary SQL queries and extract sensitive database contents.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-22214
4.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 9, 2026View on NVD →
Detail

Landray EIS is an enterprise information system designed to streamline workflows, document management, and communication processes within organizations. It is widely adopted by corporations to enhance operational efficiency, manage records, and facilitate inter-departmental collaboration. The platform offers a centralized repository for documents, enabling users to access, share, and control information seamlessly. Its user-friendly interface and integrated features make it a popular choice for businesses seeking robust document management solutions.

CVE-2025-22214 is a critical SQL Injection vulnerability that arises from insufficient input sanitization in Landray EIS. This flaw allows attackers to manipulate backend SQL queries by injecting malicious code through user-supplied input fields. The vulnerability occurs when the application fails to properly validate or escape data before incorporating it into database queries, enabling unauthorized database interactions.

Specifically, the vulnerability exists in the document management module's search or parameter handling endpoint. Attackers can exploit this by crafting malicious input in parameters such as 'id', 'keyword', or similar fields, which are directly concatenated into SQL statements without proper sanitization. This allows them to execute arbitrary SQL commands, bypass authentication, or extract sensitive data from the database.

If exploited, CVE-2025-22214 can lead to severe consequences, including unauthorized access to confidential documents, user credentials, and other sensitive enterprise data. Attackers may also modify or delete critical information, compromising data integrity and availability. The high CVSS score of 9.0 underscores the potential for significant business disruption, financial loss, and reputational damage.

Solution Advice
  • Apply the latest security patch from Landray to address CVE-2025-22214.
  • Implement parameterized queries or prepared statements for all database interactions.
  • Enforce strict input validation and sanitization on all user-supplied data, especially in document management endpoints.
  • Conduct regular security audits and penetration testing to identify and remediate similar vulnerabilities.
  • Deploy a Web Application Firewall (WAF) with rules to detect and block SQL injection attempts.
  • Restrict database user privileges to the minimum necessary for application functionality.
  • Educate developers on secure coding practices, focusing on SQL injection prevention techniques.
  • Monitor database logs for suspicious queries and implement real-time alerting for potential attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.