PT-2025-42894 · Unknown · Log2Space Subscriber Management
Published
2025-10-21
·
Updated
2025-10-21
·
CVE-2025-56450
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Log2Space Subscriber Management Software version 1.1
Description
Log2Space Subscriber Management Software version 1.1 contains a SQL injection flaw. An attacker can send a crafted POST request to the
/l2s/api/selfcareLeadHistory endpoint, exploiting the lead id parameter. The backend does not properly sanitize user input, which could allow an attacker to enumerate database schemas and table names, potentially leading to full database compromise.Recommendations
Apply input sanitization and validation to the
lead id parameter in the /l2s/api/selfcareLeadHistory endpoint.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Log2Space Subscriber Management