Aller au contenu

Fiche vulnérabilité

CVE-2025-40887 : faille moyenne nozominetworks cmc (CVSS 6.5)

Description

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
7 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • nozominetworks cmc
  • nozominetworks guardian

Références

Rechercher une autre vulnérabilité dans la base CVE