SQL Injection Vulnerability in CentrosNet by DIAL
CVE-2025-10870
9.3CRITICAL
What is CVE-2025-10870?
A SQL injection vulnerability exists in DIAL's CentrosNet v2.64, where attackers can manipulate input through the 'ultralogin' parameter in '/centrosnet/ultralogin.php'. This enables unauthorized users to retrieve, create, update, or delete database records by sending crafted POST and GET requests, raising significant security concerns for users of the application.
Affected Version(s)
CentrosNet prior to 2.65
