PT-2025-40452 · Myclub · Myclub
William Fieldhouse
·
Published
2025-10-02
·
Updated
2025-10-03
·
CVE-2025-57423
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MyClub version 0.5
Description
A SQL injection issue exists in MyClub version 0.5. Insufficient input sanitisation in the
/articles API endpoint allows an unauthenticated remote attacker to inject arbitrary SQL commands via a crafted GET request. The vulnerable query parameters include Content, GroupName, PersonName, lastUpdate, pool, and title. Successful exploitation could lead to information disclosure or database manipulation.Recommendations
Apply input sanitisation to all query parameters of the
/articles endpoint.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myclub