HIGH🇵🇱 Wersja polska

CVE-2025-40886

CVSS 7.7v4.0pub. 2025-10-07upd. 2025-10-09

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and content, and/or affecting their availability.

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Nozominetworks Cmc

    APP
    Nozominetworks
    < 25.2.0
  • Nozominetworks Guardian

    APP
    Nozominetworks
    < 25.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-29245CRITICAL9.2PL ✓same product

SQL Injection w Nozomi Networks Guardian i CMC — nieuwierzytelniony dostęp do bazy danych

CVE-2026-31984HIGH8.7PL ✓same product

DoS przez nieograniczoną alokację zasobów w logowaniu audytu — Nozomi Networks

CVE-2026-33390HIGH7.2PL ✓same product

Nieprawidłowe przypisanie uprawnień w Nozomi Networks CMC i Guardian

CVE-2025-40892HIGH7.1same product

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper valida...

CVE-2025-40898HIGH7.2same product

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient...