An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
History

Thu, 12 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rsiqueue
Rsiqueue management System
CPEs cpe:2.3:a:rsiqueue:management_system:3.0:*:*:*:*:*:*:*
Vendors & Products Rsiqueue
Rsiqueue management System

Tue, 20 May 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 May 2025 15:45:00 +0000

Type Values Removed Values Added
References

Tue, 20 May 2025 14:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-20T15:32:56.530Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-26086

cve-icon Vulnrichment

Updated: 2025-05-20T15:04:09.133Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-20T15:16:07.023

Modified: 2025-06-12T16:20:56.180

Link: CVE-2025-26086

cve-icon Redhat

No data.