Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-15T13:18:57.300Z
Reserved: 2025-04-15T00:00:00.000Z
Link: CVE-2025-32993
Updated: 2025-04-15T13:18:48.980Z
Status : Deferred
Published: 2025-04-15T06:15:43.857
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-32993
No data.