PT-2026-1108 · Daptin · Daptin

Hiro

·

Published

2026-01-02

·

Updated

2026-01-02

·

CVE-2025-15439

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Daptin version 0.10.3
Description A flaw exists in Daptin version 0.10.3 within the Aggregate API component. Specifically, the goqu.L function in the server/resource/resource aggregate.go file is susceptible to SQL injection. The issue arises from the manipulation of the column, group, or order arguments. This issue can be exploited remotely. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15439

Affected Products

Daptin