PT-2025-18769 · Mydata Informatics · Mydata Informatics Ticket Sales Automation

Published

2025-05-02

·

Updated

2025-05-07

·

CVE-2025-2812

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mydata Informatics Ticket Sales Automation versions prior to 03.04.2025
Description The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows for Blind SQL Injection.
Recommendations For versions prior to 03.04.2025, as a temporary workaround, consider restricting access to sensitive SQL commands until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-2812

Affected Products

Mydata Informatics Ticket Sales Automation