PT-2026-6738 · Rimbalinux · Ahadpos

Cakes

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2019-25299

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions RimbaLinux AhadPOS version 1.11
Description An issue exists where crafted POST requests can manipulate database queries via the alamatCustomer parameter. This allows for the use of time-based and boolean-based blind SQL injection techniques to extract information or interact with the underlying database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25299

Affected Products

Ahadpos