HIGH
Nominas 0.27 SQL Injection via username Parameter
Published Mar 6, 2026
8.8
HIGHCVSS 4.0
EPSS 0.32%
Description
Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username parameter. Attackers can send POST requests to the login/checklogin.php endpoint with crafted UNION-based SQL injection payloads to extract database information including usernames, database names, and version details.
Affected products
-
- Version 0.27StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://www.exploit-db.com/exploits/45820 exploit
- https://www.vulncheck.com/advisories/nominas-sql-injection-via-username-parameter third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.exploit-db.com/exploits/45820 | exploit | |
| https://www.vulncheck.com/advisories/nominas-sql-injection-via-username-parameter | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 6, 2026
Updated Mar 9, 2026
Reserved Mar 6, 2026
Link CVE-2018-25194
CISA Vulnrichment
Updated Mar 9, 2026