SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'.
History

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Zeon Global Tech
Zeon Global Tech zeon Academy Pro
Vendors & Products Zeon Global Tech
Zeon Global Tech zeon Academy Pro

Tue, 21 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'.
Title SQL injection in Zeon Academy Pro by Zeon Global Tech
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-04-21T14:59:40.481Z

Updated: 2026-04-21T16:23:02.186Z

Reserved: 2025-04-16T09:09:26.929Z

Link: CVE-2025-41029

cve-icon Vulnrichment

Updated: 2026-04-21T16:22:41.615Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-21T16:16:19.350

Modified: 2026-04-21T16:20:24.180

Link: CVE-2025-41029

cve-icon Redhat

No data.