PT-2026-3025 · Itflow · Itflow

Published

2026-01-15

·

Updated

2026-01-17

·

CVE-2025-67081

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Itflow versions through 25.06
Description An SQL injection issue exists in Itflow due to insufficient sanitization of integer parameters. Specifically, the "role id" parameter is vulnerable when editing a profile. An attacker with administrative privileges can exploit this through blind SQL injection to extract arbitrary data from the database. The vulnerable parameter is role id.
Recommendations Versions prior to 25.06 should be updated. Ensure proper sanitization of the role id parameter when editing profiles.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67081

Affected Products

Itflow