SQL Injection Vulnerability in Allims lab.online Product
CVE-2025-1157

5.3MEDIUM

Key Information:

Vendor
Allims
Status
Lab.online
Vendor
CVE Published:
10 February 2025

Summary

A significant vulnerability exists in the Allims lab.online product due to improper handling of user input in the /model/model_recuperar_senha.php file. This weakness allows attackers to manipulate the 'recuperacao' argument, leading to SQL injection attacks that can be initiated remotely. The vulnerability poses a serious risk as attackers, once exploiting this flaw, could potentially gain unauthorized access to sensitive data. Despite early disclosure to the vendor, there has been no response or action taken to remediate the issue, raising further alarm regarding the security of their web application.

Affected Version(s)

lab.online 20250201

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stux (VulDB User)
Stux (VulDB User)
.