PT-2026-23687 · Unknown · Alienor Web Libre
Published
2026-03-06
·
Updated
2026-03-06
·
CVE-2018-25175
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Alienor Web Libre version 2.0
Description
Alienor Web Libre 2.0 contains an SQL injection issue that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests to the ''index.php'' endpoint with SQL injection payloads through the
identifiant parameter. This allows extraction of sensitive database information, including usernames, databases, and version details.Recommendations
Apply a fix to sanitize the
identifiant parameter in the ''index.php'' endpoint to prevent SQL injection attacks.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alienor Web Libre