CVE-2025-52924

Publication date

2025-07-19 00:00:00

Family

mitre

State

PUBLISHED

Description

In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.