PT-2026-3025 · Itflow · Itflow

Publicado

2026-01-15

·

Atualizado

2026-01-17

·

CVE-2025-67081

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Itflow versions through 25.06
Description An SQL injection issue exists in Itflow due to insufficient sanitization of integer parameters. Specifically, the "role id" parameter is vulnerable when editing a profile. An attacker with administrative privileges can exploit this through blind SQL injection to extract arbitrary data from the database. The vulnerable parameter is role id.
Recommendations Versions prior to 25.06 should be updated. Ensure proper sanitization of the role id parameter when editing profiles.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67081

Produtos afetados

Itflow