PT-2025-4533 · Unknown · Ofek Nakar Virtual Bot

Caesar Evan Santoso

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2025-22542

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Ofek Nakar Virtual Bot versions prior to 1.0.0
Description The issue is related to the improper neutralization of special elements used in an SQL command, allowing for Blind SQL Injection. This means an attacker can execute SQL commands without directly seeing the database output, potentially leading to data extraction or modification.
Recommendations For versions prior to 1.0.0, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to SQL commands or implementing additional validation and sanitization for user input to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22542

Affected Products

Ofek Nakar Virtual Bot