PT-2026-23697 · Unknown · Tina4 Stack

Published

2026-03-06

·

Updated

2026-03-16

·

CVE-2018-25187

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tina4 Stack version 1.0.3
Description Tina4 Stack version 1.0.3 has multiple issues that allow unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes. SQL code can be injected through the /menu API endpoint to manipulate database queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2018-25187

Affected Products

Tina4 Stack