ROBERT KRUCZEK
← Back to home

CVE-2025-3893

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS v4.0: 8.6 (HIGH) Published: May 23, 2025 View on NVD →

Description

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. 
Version 5.20 of MegaBIP fixes this issue.

Affected Products

Vendor Product Versions Affected
Jan Syski MegaBIP 0 (<= 5.19) (affected)

CVSS Score & Vector

Base Score: 8.6 (HIGH)
Vector (v4.0):
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Credits / Discoverer

  • Kamil Szczurowski
  • Robert Kruczek