SQL Injection Vulnerability in JoeyBling Bootplus Application
CVE-2025-0698
Key Information:
- Vendor
- Joeybling
- Status
- Bootplus
- Vendor
- CVE Published:
- 24 January 2025
Badges
Summary
A SQL injection vulnerability exists within the JoeyBling bootplus application, specifically in the /admin/sys/menu/list functionality. By manipulating the sort/order parameters, an attacker can execute unauthorized SQL commands remotely. This vulnerability has been publicly disclosed and poses a significant security risk, as continuous delivery practices and rolling releases hinder the availability of specific version information for affected or patched versions.
Affected Version(s)
bootplus 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved