PT-2025-23910 · Unknown · 2Clickportal

Kamil Szczurowski

+1

·

Published

2025-06-05

·

Updated

2025-06-05

·

CVE-2025-4568

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions 2ClickPortal versions prior to 7.14.3
Description The issue is related to improper neutralization of input provided by an unauthorized user into the changes reference id parameter in the URL, allowing for boolean-based Blind SQL Injection attacks. This is a result of CWE-89, Improper Neutralization of Special Elements used in an SQL Command, also known as SQL Injection.
Recommendations For 2ClickPortal versions prior to 7.14.3, update to version 7.14.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the changes reference id parameter in the URL to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4568

Affected Products

2Clickportal