PT-2025-46995 · Unknown · Svx Portal

Published

2025-11-14

·

Updated

2025-11-14

·

CVE-2025-63724

CVSS v3.1

6.0

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions SVX Portal version 2.7A
Description A SQL injection flaw exists in SVX Portal version 2.7A. This issue is triggered by a specially crafted POST request sent to the /admin/update setings.php endpoint. Successful exploitation could allow an attacker to manipulate database queries. The vulnerable parameter is not explicitly specified.
Recommendations Apply updates to address the issue in SVX Portal version 2.7A. As a temporary workaround, restrict access to the /admin/update setings.php endpoint.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63724

Affected Products

Svx Portal