SQL Injection Vulnerability in PostaPanduri Plugin by Adrian Ladó
CVE-2025-49452
9.3CRITICAL
What is CVE-2025-49452?
The PostaPanduri plugin developed by Adrian Ladó contains a security flaw that permits improper neutralization of special elements utilized in SQL commands. This SQL Injection vulnerability can be exploited to manipulate database queries, leading to unauthorized access to sensitive data. The issue impacts all versions of PostaPanduri up to and including version 2.1.3, necessitating prompt attention from users to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PostaPanduri <= 2.1.3
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Kim Sang (Patchstack Alliance)