CRITICAL🇵🇱 Wersja polska

CVE-2025-51535

CVSS 9.1v3.1pub. 2025-08-04upd. 2025-09-20

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-1392 (Use of Default Credentials) combined with the SQLi tag suggests that attackers with administrative privileges can inject unvalidated SQL queries through the application's administrative interface. According to vendor references, the issue concerns an unrestricted SQL console available in the administrative panel (Admin UI). Lack of proper input validation enables execution of arbitrary queries directly on the database.

Impact

An attacker can gain full access to the application database, read, modify, or delete stored archaeological and configuration data, and potentially perform operations at the database system level, leading to violations of confidentiality, integrity, and availability of the entire system.

Mitigation & patch

Apply patches available from the vendor according to the references. Additionally, it is recommended to restrict access to the administrative panel only to trusted networks and implement strong access control for the SQL console in the Admin UI.

Who is affected

OpenAtlas version 8.11.0 developed by the Austrian Archaeological Institute

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Craws Openatlas

    APP
    Craws
    < 8.12.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-51536CRITICAL9.8PL ✓same product

Hardcoded hasło administratora w OpenAtlas v8.11.0

CVE-2025-60915HIGH8.1same product

An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8...

CVE-2025-51534HIGH8.1same product

A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows ...

CVE-2025-60914MEDIUM4.6same product

Nieprawidłowa kontrola dostępu w Austrian Archaeological Institute Openatlas przed wersją v8.12.0 pozwala atak...

CVE-2025-56423MEDIUM5.3same product

Podatność w Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 pozwala zda...