SQL Injection Vulnerability in Metagauss ProfileGrid Software
CVE-2025-49876
8.5HIGH
What is CVE-2025-49876?
The Metagauss ProfileGrid software is exposed to an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands. This flaw allows an attacker to manipulate SQL queries, potentially leading to unauthorized data access and exposure. Users of ProfileGrid versions n/a through 5.9.5.2 should take immediate steps to evaluate their security measures and apply necessary patches.
Affected Version(s)
ProfileGrid <= 5.9.5.2
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)