SQL Injection Vulnerability in LambertGroup Sticky Radio Player
CVE-2025-31926 
8.5HIGH
What is CVE-2025-31926?
The Sticky Radio Player developed by LambertGroup contains a vulnerability that allows for SQL injection due to improper handling of special elements within SQL commands. This flaw affects versions up to 3.4, enabling attackers to manipulate database queries, potentially leading to unauthorized data access and disruption of services.
Affected Version(s)
Sticky Radio Player <= 3.4
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
 None
Availability:
 High
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 Low
User Interaction:
 None
Scope:
 Changed
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)