PT-2025-29936 · Unknown · Nbcio-Boot

Cafe-Tea

·

Published

2025-07-17

·

Updated

2025-07-22

·

CVE-2025-50240

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nbcio-boot version 1.0.3
Description nbcio-boot version 1.0.3 contains a SQL injection issue via the userIds parameter at the /sys/user/deleteRecycleBin API endpoint.
Recommendations nbcio-boot version 1.0.3: Sanitize or validate the userIds parameter before using it in SQL queries to prevent injection attacks. nbcio-boot version 1.0.3: Implement parameterized queries or prepared statements to ensure that user-supplied input is treated as data rather than executable code. nbcio-boot version 1.0.3: As a temporary workaround, restrict access to the /sys/user/deleteRecycleBin API endpoint until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-50240

Affected Products

Nbcio-Boot