External risk intelligence

Epsilon RH SQL Injection Vulnerability Allows Database Manipulation.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-41028

The vulnerability exists in a web service (.asmx) endpoint within an HR management application. Such applications and their associated web service interfaces are frequently deployed as internet-facing components to facilitate remote access for employees and system integration, making them a common target for public network exposure.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A SQL Injection vulnerability has been discovered in Epsilon RH by Grupo Castilla, affecting its web services. This flaw could potentially allow unauthorized access and modification of sensitive database information. The main concern is confirming its relevance and exposure within our environment.

  • Database data access flaw.
  • Confirms HR system external exposure.
  • Verify relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this SQL Injection vulnerability by sending a specially crafted POST request to the `/epsilonnetws/WSAvisos.asmx` endpoint. By manipulating the `sEstadoUsr` parameter, an attacker could interact directly with the application's database, potentially leading to unauthorized data access, modification, or deletion.

  • Entry condition: Public network exposure.
  • Trigger point: Manipulating a POST request parameter.
  • Resulting risk: Unauthorized database access and modification.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in Epsilon RH could allow an unauthenticated attacker to manipulate the application's database by sending specially crafted POST requests. This could affect database integrity and confidentiality when the web service is accessible over the network.

  • Database data and integrity.
  • Via POST requests to a web service.
  • Data manipulation and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in an HR management application's web service likely requires action from the application owner, infrastructure team, and security team. The first practical step is to identify all instances of the affected application, confirm their accessibility and criticality, and then coordinate remediation efforts with the vendor and internal teams.

  • Application owners should lead remediation efforts.
  • Verify application reachability and business impact.
  • Coordinate with vendor for a timely fix.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Epsilon RH by Grupo Castilla?

Epsilon RH is an enterprise human resources management application designed to handle employee data and organizational administrative tasks. It includes web service components, such as those used for notification or system integration, which allow the platform to communicate with other tools or facilitate remote employee access to HR functions.

What does SQL Injection mean for CVE-2025-41028?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. It means the software does not properly sanitize user input, allowing an attacker to inject their own malicious database commands. In this specific case, it allows an unauthorized party to read, modify, or even delete records within the application's backend database.

How is this SQL injection triggered?

The vulnerability is triggered by sending a crafted HTTP POST request to the specific web service endpoint '/epsilonnetws/WSAvisos.asmx'. By inserting malicious SQL syntax into the 'sEstadoUsr' parameter of that request, the application is tricked into executing the attacker's commands. Simply browsing the site or sending standard GET requests without this specific parameter manipulation does not trigger the flaw.

Why does Halo Surface Signal categorize this as an external threat?

Halo Surface Signal identifies this as a significant concern because the vulnerability resides in a web service interface (.asmx) commonly designed for remote access or system integrations. Because these interfaces are frequently deployed as internet-facing components to enable connectivity for off-site employees, they are often reachable from the public internet, which increases the likelihood of unauthorized access attempts.

What is the first step for teams using Epsilon RH?

You should begin by performing an internal inventory to locate every instance of the Epsilon RH software within your environment. Once identified, evaluate which systems are exposed to the network and determine their business criticality. Coordinate immediately with your application owners and the software vendor to confirm the availability of patches or specific configuration changes to secure the affected web service.