Beveiligingsadvies

CVE-2025-3893

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-23 10:20:02
Laatst bijgewerkt 2025-05-23 12:13:22
Toegewezen door CERT-PL
CVSS-score 8.6
Status PUBLISHED

Beschrijving

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.