CVE-2025-0929
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-0929 is a newly discovered SQL injection vulnerability affecting TeamCal Neo, version 3.8.2. An attacker can exploit this flaw by injecting malicious SQL statements into the ‘abs’ parameter in ‘/teamcal/src/index.php’. Successful exploitation grants the attacker unauthorized access to retrieve, update, and even delete all database information, potentially leading to significant data loss or unauthorized system access. This vulnerability poses a serious threat to organizations using TeamCal Neo and emphasizes the importance of keeping software up-to-date with security patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.