PT-2025-49893 · Unknown · Artplacer Widget

Published

2025-12-09

·

Updated

2025-12-15

·

CVE-2025-67517

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions artplacer ArtPlacer Widget versions through 2.22.9.2
Description The ArtPlacer Widget software contains a flaw due to improper neutralization of special elements within SQL commands, leading to a Blind SQL Injection condition. This allows for potential unauthorized access to or modification of data within the database.
Recommendations Update to a version later than 2.22.9.2.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-67517

Affected Products

Artplacer Widget