PT-2025-39970 · Bip+2 · Bip+2

Mikołaj Matuszewski

·

Publicado

2025-09-30

·

Atualizado

2025-09-30

·

CVE-2025-8121

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description The issue involves improper neutralization of input provided by an authorized user within the article positioning functionality, leading to potential Blind SQL Injection attacks. This affects all three templates: www, bip, and ww+bip. The product is End-Of-Life, and the producer will not release patches to address this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8121

Produtos afetados

Bip
Ww+Bip
Www