PT-2026-23697 · Unknown · Tina4 Stack

CVE-2018-25187

·

Published

2026-03-06

·

Updated

2026-03-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tina4 Stack version 1.0.3
Description Tina4 Stack version 1.0.3 has multiple issues that allow unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes. SQL code can be injected through the /menu API endpoint to manipulate database queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25187

Affected Products

Tina4 Stack