Back

CRITICAL

SQL injection on the virtual campus platform of Diseño de Recursos Educativos

Published Oct 27, 2025

Description

SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using the ‘buscame’ parameter in ‘/catalogo_c/catalogo.php’.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Oct 27, 2025
Updated Oct 27, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Oct 27, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a