SQL Injection Vulnerability in LambertGroup Chameleon HTML5 Audio Player
CVE-2025-32307

8.5HIGH

What is CVE-2025-32307?

A vulnerability exists in LambertGroup's Chameleon HTML5 Audio Player, which allows an attacker to exploit improper neutralization of special elements in SQL commands, leading to SQL injection attacks. This issue affects users of the player from version 3.5.6 and earlier, potentially exposing sensitive data and compromising database integrity.

Affected Version(s)

Chameleon HTML5 Audio Player With/Without Playlist <= 3.5.6

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
The Cyber Security Vulnerability Database.