An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsiqueue
Rsiqueue management System |
|
| CPEs | cpe:2.3:a:rsiqueue:management_system:3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Rsiqueue
Rsiqueue management System |
Tue, 20 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 20 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-05-20T00:00:00.000Z
Updated: 2025-05-20T15:32:56.530Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26086
Updated: 2025-05-20T15:04:09.133Z
Status : Analyzed
Published: 2025-05-20T15:16:07.023
Modified: 2025-06-12T16:20:56.180
Link: CVE-2025-26086
No data.