SQL Injection Vulnerability in WIMP Platform by HAMASTAR Technology
CVE-2025-6169
9.3CRITICAL
What is CVE-2025-6169?
The WIMP website co-construction management platform developed by HAMASTAR Technology is vulnerable to a SQL Injection, which permits unauthenticated remote attackers to execute arbitrary SQL commands. This can lead to the unauthorized reading, modification, or deletion of database contents, posing a significant risk to the integrity and confidentiality of sensitive information.
Affected Version(s)
WIMP 0 <= 5.3.1.34642