PT-2026-23697 · Unknown · Tina4 Stack

CVE-2018-25187

·

Publicado

2026-03-06

·

Atualizado

2026-03-16

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tina4 Stack version 1.0.3
Description Tina4 Stack version 1.0.3 has multiple issues that allow unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes. SQL code can be injected through the /menu API endpoint to manipulate database queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-25187

Produtos afetados

Tina4 Stack