Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2025-0018
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Change Log
2025-11-27 - Initial publication 2026-03-04 - Updated fix version from 2025.3.9 to 2025.3.10
SQL injection in last usage logs
9.4 Critical - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
An SQL injection via the DateSortField parameter in last usage logs allows authenticated users to exfiltrate or modify data.
CVE(s)
CVE-2025-13757
Credits
JaGoTu, DCIT a.s.
Credentials included in partial connection requests
Medium 5.1 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Entries in DVLS are requested in two separate requests, the first request contains general information to be displayed such as the name, username, creation date etc. Credentials such as passwords are fetched via a /sensitive-data request when the credential is accessed by the user. Some entry types improperly included passwords in the first request.
CVE(s)
CVE-2025-13758
Credits
JaGoTu, DCIT a.s.
Improper access control in email service component
4.9 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:H/SA:N
The email service configuration API returned email service passwords to users without administrative rights when multiple email services where configured.
CVE(s)
CVE-2025-13765
Remediation and Workarounds
Upgrade to Devolutions Server 2025.2.21 or higher; 2025.3.10 or higher