PT-2025-51283 · Sunbird · Power Iq

Published

2025-12-15

·

Updated

2025-12-30

·

CVE-2025-55703

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sunbird Power IQ versions prior to 9.2.1
Description An error-based SQL injection issue exists in the Power IQ API due to insufficient input validation when handling arrays in an outdated API endpoint. This allows manipulation of SQL queries.
Recommendations Update to Power IQ version 9.2.1 or later, which includes updated API call code for safe handling of input values.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-55703

Affected Products

Power Iq