SQL Injection Vulnerability in LambertGroup Chameleon HTML5 Audio Player
CVE-2025-32307
8.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 May 2025
What is CVE-2025-32307?
A vulnerability exists in LambertGroup's Chameleon HTML5 Audio Player, which allows an attacker to exploit improper neutralization of special elements in SQL commands, leading to SQL injection attacks. This issue affects users of the player from version 3.5.6 and earlier, potentially exposing sensitive data and compromising database integrity.
Affected Version(s)
Chameleon HTML5 Audio Player With/Without Playlist <= 3.5.6
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)