SQL Injection Vulnerability in Allims lab.online Product
CVE-2025-1157
What is CVE-2025-1157?
A significant vulnerability exists in the Allims lab.online product due to improper handling of user input in the /model/model_recuperar_senha.php file. This weakness allows attackers to manipulate the 'recuperacao' argument, leading to SQL injection attacks that can be initiated remotely. The vulnerability poses a serious risk as attackers, once exploiting this flaw, could potentially gain unauthorized access to sensitive data. Despite early disclosure to the vendor, there has been no response or action taken to remediate the issue, raising further alarm regarding the security of their web application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lab.online 20250201
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
