PT-2025-39970 · Bip+2 · Bip+2
Mikołaj Matuszewski
·
Publicado
2025-09-30
·
Atualizado
2025-09-30
·
CVE-2025-8121
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined. (affected versions not specified)
Description
The issue involves improper neutralization of input provided by an authorized user within the article positioning functionality, leading to potential Blind SQL Injection attacks. This affects all three templates:
www, bip, and ww+bip. The product is End-Of-Life, and the producer will not release patches to address this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bip
Ww+Bip
Www