PT-2025-51443 · Unknown · Stefano Lissa Newsletter

Published

2025-12-16

·

Updated

2025-12-17

·

CVE-2025-67999

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Stefano Lissa Newsletter versions through 9.0.9
Description A flaw exists in Stefano Lissa Newsletter that allows for Blind SQL Injection due to Improper Neutralization of Special Elements used in an SQL Command. This issue could potentially allow an attacker to manipulate database queries.
Recommendations Update Stefano Lissa Newsletter to a version later than 9.0.9.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-67999

Affected Products

Stefano Lissa Newsletter