Back

MEDIUM

Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0

Published Oct 7, 2025

Description

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.

Affected products

Remediation

Vendor solution

Upgrade to v25.2.0 or later.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Nozomi
Published Oct 7, 2025
Updated Oct 7, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Oct 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a