PT-2025-16253 · Unknown · Sicommnet Basec
Frank Breedijk
+1
·
Published
2025-04-14
·
Updated
2025-04-21
·
CVE-2025-22371
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:Y/V:C |
Name of the Vulnerable Software and Affected Versions:
SicommNet BASEC (SaaS Service) versions prior to the fixed version, which is not specified.
Description:
The issue is related to an SQL Injection vulnerability in the login page of SicommNet BASEC, allowing an unauthenticated remote attacker to bypass authentication and execute arbitrary SQL commands. This vulnerability has been present in the solution at least since December 14, 2021, and likely before that.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicommnet Basec