Blind SQL Injection Vulnerability in 2Click Portal by R.E. Software
CVE-2025-4568

9.3CRITICAL

Key Information:

Vendor
CVE Published:
5 June 2025

What is CVE-2025-4568?

The vulnerability in the 2Click Portal arises from improper handling of input transmitted through the changes__reference_id parameter in the URL. This flaw allows unauthorized users to perform boolean-based Blind SQL Injection attacks, which can lead to unauthorized data access and manipulation. It is crucial for users to apply the necessary patches and security measures to safeguard their applications against potential exploitation.

Affected Version(s)

2ClickPortal 0 < 7.14.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.
CVE-2025-4568 : Blind SQL Injection Vulnerability in 2Click Portal by R.E. Software