PT-2025-36543 · Uverif · Uverif

Zxpression

·

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-10121

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: uverif versions prior to 3.3
Description: A flaw has been found in uverif that allows for SQL injection. The issue is located in the addbatch function within the /admin/kami list file. Manipulation of the note argument can trigger the injection. This issue is potentially exploitable remotely.
Recommendations: As a temporary workaround, consider restricting access to the /admin/kami list file. Avoid using the note parameter in the addbatch function until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10121

Affected Products

Uverif