PT-2025-39971 · Ww+Bip+2 · Ww+Bip+2

Mikołaj Matuszewski

·

Published

2025-09-30

·

Updated

2025-09-30

·

CVE-2025-8122

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description The issue involves improper neutralization of input provided by an authorized user in the article positioning functionality, leading to Blind SQL Injection attacks. This affects all three templates: 'www', 'bip', and 'ww+bip'. The product is End-Of-Life, and the producer will not release patches to address this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-8122

Affected Products

Bip
Ww+Bip
Www