SQL Injection Vulnerability in Multimedia Responsive Carousel by LambertGroup
CVE-2025-31928

8.5HIGH

What is CVE-2025-31928?

An SQL Injection vulnerability exists in the Multimedia Responsive Carousel that allows attackers to manipulate SQL queries through specially crafted input. This can lead to unauthorized access to sensitive data or compromise the integrity of the database. The affected version is prior to 2.6.0, which fails to properly neutralize special elements in SQL commands, leaving systems exposed to potential database exploitation. It is crucial for users of the affected product to upgrade to the latest version to safeguard against this vulnerability.

Affected Version(s)

Multimedia Responsive Carousel with Image Video Audio Support <= 2.6.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
CVE-2025-31928 : SQL Injection Vulnerability in Multimedia Responsive Carousel by LambertGroup