SQL Injection Vulnerability in Allims lab.online Product
CVE-2025-1157
5.3MEDIUM
Key Information:
- Vendor
- Allims
- Status
- Lab.online
- Vendor
- CVE Published:
- 10 February 2025
Summary
A significant vulnerability exists in the Allims lab.online product due to improper handling of user input in the /model/model_recuperar_senha.php file. This weakness allows attackers to manipulate the 'recuperacao' argument, leading to SQL injection attacks that can be initiated remotely. The vulnerability poses a serious risk as attackers, once exploiting this flaw, could potentially gain unauthorized access to sensitive data. Despite early disclosure to the vendor, there has been no response or action taken to remediate the issue, raising further alarm regarding the security of their web application.
Affected Version(s)
lab.online 20250201
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Stux (VulDB User)
Stux (VulDB User)