HIGH🇬🇧 English

CVE-2025-40886

CVSS 7.7v4.0pub. 2025-10-07upd. 2025-10-09

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and content, and/or affecting their availability.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Nozominetworks Cmc

    APP
    Nozominetworks
    < 25.2.0
  • Nozominetworks Guardian

    APP
    Nozominetworks
    < 25.2.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SQLi
CWE
Referencje

Powiązane podatności

CVE-2023-29245CRITICAL9.2PL ✓ten sam produkt

SQL Injection w Nozomi Networks Guardian i CMC — nieuwierzytelniony dostęp do bazy danych

CVE-2026-31984HIGH8.7PL ✓ten sam produkt

DoS przez nieograniczoną alokację zasobów w logowaniu audytu — Nozomi Networks

CVE-2026-33390HIGH7.2PL ✓ten sam produkt

Nieprawidłowe przypisanie uprawnień w Nozomi Networks CMC i Guardian

CVE-2025-40892HIGH7.1ten sam produkt

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper valida...

CVE-2025-40898HIGH7.2ten sam produkt

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient...