Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.
History

Tue, 29 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Ncvav
Ncvav virtual Pbx Software
Vendors & Products Ncvav
Ncvav virtual Pbx Software

Mon, 28 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.
Title SQLi in Ncvav's Virtual PBX Software
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published: 2025-07-28T11:05:16.203Z

Updated: 2025-07-28T14:32:37.380Z

Reserved: 2025-06-30T08:17:12.538Z

Link: CVE-2025-6918

cve-icon Vulnrichment

Updated: 2025-07-28T14:32:26.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-28T11:15:25.257

Modified: 2025-07-29T14:14:29.590

Link: CVE-2025-6918

cve-icon Redhat

No data.