PT-2025-5939 · Sudipto+1 · Sudipto+1

Tri Doan

·

Published

2025-02-07

·

Updated

2025-02-12

·

CVE-2025-25116

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions sudipto Link to URL / Post versions n/a through 1.3
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as a SQL Injection vulnerability. This allows for Blind SQL Injection.
Recommendations For versions n/a through 1.3, consider disabling the SQL command functionality until a patch is available. As a temporary workaround, restrict access to the /Post endpoint to minimize the risk of exploitation. Avoid using special elements in SQL commands in the affected Link to URL / Post until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-25116

Affected Products

Link To Url
Sudipto