PT-2025-31257 · Unknown · Bacula-Web

Published

2025-07-29

·

Updated

2025-07-29

·

CVE-2025-45346

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bacula-web versions prior to 9.7.1
Description A SQL Injection issue exists in Bacula-web. A remote attacker can execute arbitrary code via a crafted HTTP GET request.
Recommendations Update Bacula-web to version 9.7.1 or later.

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-45346
GHSA-HQ25-VP56-QR86

Affected Products

Bacula-Web