PT-2025-29936 · Unknown · Nbcio-Boot
Cafe-Tea
·
Published
2025-07-17
·
Updated
2025-07-22
·
CVE-2025-50240
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
nbcio-boot version 1.0.3
Description
nbcio-boot version 1.0.3 contains a SQL injection issue via the
userIds parameter at the /sys/user/deleteRecycleBin API endpoint.Recommendations
nbcio-boot version 1.0.3: Sanitize or validate the
userIds parameter before using it in SQL queries to prevent injection attacks.
nbcio-boot version 1.0.3: Implement parameterized queries or prepared statements to ensure that user-supplied input is treated as data rather than executable code.
nbcio-boot version 1.0.3: As a temporary workaround, restrict access to the /sys/user/deleteRecycleBin API endpoint until a patch is available.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nbcio-Boot