MEDIUM
JoeyBling bootplus list sql injection
Published Jan 24, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.42%
Description
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sys/role/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
Affected products
-
- Version StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1822 Advisory
- https://github.com/JoeyBling/bootplus/issues/21 issue-trackingNot Applicable
- https://github.com/JoeyBling/bootplus/issues/21#issue-2786893665 exploitissue-trackingNot Applicable
- https://vuldb.com/?ctiid.293227 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.293227 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.480836 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1822 | Advisory | |
| https://github.com/JoeyBling/bootplus/issues/21 | issue-trackingNot Applicable | |
| https://github.com/JoeyBling/bootplus/issues/21#issue-2786893665 | exploitissue-trackingNot Applicable | |
| https://vuldb.com/?ctiid.293227 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.293227 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.480836 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 24, 2025
Updated Feb 12, 2025
Reserved Jan 24, 2025
Link CVE-2025-0699
CISA Vulnrichment
Updated Jan 24, 2025
ENISA EUVD
EUVD-2025-1822 Assigner VulDB
Published Jan 24, 2025
Updated Feb 12, 2025
Exploited since n/a
Link EUVD-2025-1822