PT-2026-43231 · Unknown · Collectric Cmu

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2018-25379

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Collectric CMU version 1.0
Description An issue exists where unauthenticated attackers can manipulate database queries during authentication. This is achieved by injecting SQL code through the lang parameter in login requests, allowing the extraction of sensitive information from the database using boolean-based and time-based blind techniques. Blind SQL injection is a method where an attacker asks the database true or false questions and determines the answer based on the application's response or the time it takes to respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2018-25379

Affected Products

Collectric Cmu