PT-2025-32418 · Unknown · Cesiumlab Web

Threez

·

Published

2025-08-08

·

Updated

2025-08-09

·

CVE-2025-8744

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CesiumLab Web versions prior to 4.1
Description A critical vulnerability exists in CesiumLab Web. The issue affects unknown code within the /lodmodels/ file and allows for SQL injection through manipulation of the ID argument. This attack can be initiated remotely. The exploit has been publicly disclosed, and the vendor was informed but did not respond.
Recommendations Update CesiumLab Web to version 4.1 or later.

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8744

Affected Products

Cesiumlab Web