PT-2025-5852 · Emoncms · Emoncms

Yichaoxu

·

Published

2025-02-06

·

Updated

2025-07-30

·

CVE-2025-22992

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Emoncms versions 11.6.9 and later
Description A SQL Injection vulnerability exists due to improper handling of user-supplied input in the data query parameter. This allows attackers to execute arbitrary SQL commands under specific conditions.
Recommendations Emoncms versions 11.6.9 and later: As a temporary workaround, consider restricting access to the /feed/insert.json endpoint until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22992

Affected Products

Emoncms