PT-2025-20910 · Owl-Admin · Owladmin

Ltltlxey

·

Published

2025-05-13

·

Updated

2025-07-09

·

CVE-2025-28057

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: owl-admin versions 3.2.2 through 4.10.2
Description: The issue is related to SQL Injection in the "/admin-api/system/admin menus/save order" API endpoint.
Recommendations: For versions 3.2.2 through 4.10.2, consider disabling access to the "/admin-api/system/admin menus/save order" API endpoint until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-28057

Affected Products

Owladmin