Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gurmehub Kargo Entegratör allows SQL Injection. This issue affects Kargo Entegratör: from n/a through 1.1.14.
History

Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gurmehub Kargo Entegratör allows SQL Injection. This issue affects Kargo Entegratör: from n/a through 1.1.14.
Title WordPress Kargo Entegratör plugin <= 1.1.14 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2025-04-15T21:53:11.785Z

Updated: 2025-04-16T13:44:08.081Z

Reserved: 2025-02-17T11:50:52.140Z

Link: CVE-2025-26908

cve-icon Vulnrichment

Updated: 2025-04-16T13:43:23.087Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-15T22:15:18.057

Modified: 2025-04-16T13:25:37.340

Link: CVE-2025-26908

cve-icon Redhat

No data.