PT-2026-23704 · Nominas · Nominas

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2018-25194

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nominas version 0.27
Description An SQL injection issue exists in Nominas 0.27 that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can send POST requests to the ''/login/checklogin.php'' endpoint with crafted UNION-based SQL injection payloads through the username parameter. This allows extraction of database information, including usernames, database names, and version details.
Recommendations Update to a newer version of Nominas that addresses this vulnerability. As a temporary workaround, restrict access to the ''/login/checklogin.php'' endpoint. Sanitize the username parameter to prevent SQL injection attacks.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2018-25194

Affected Products

Nominas