A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.
Publication date: Mon, 21 Jul 2025 09:30:00 +0000
Cyber News related to CVE-2025-41678
CVE-2025-41678 - A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. ...
5 months ago
CVE-2021-41678 - A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter. ...
4 years ago
CVE-2023-41678 - A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request. ...
2 years ago Tenable.com
CVE-2022-41678 - Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. ...
1 year ago
CVE-2024-41678 - GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to exploit a reflected XSS vulnerability. Upgrade to 10.0.17. ...
1 year ago Tenable.com