CVE-2025-22502

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 89

Summary

CVE-2025-22502 is an SQL Injection vulnerability affecting MindValley Super PageMash from an undisclosed version up to 1.1. Hackers can exploit this weakness by inserting malicious SQL commands into inputs, enabling unauthorized data access or manipulation. This issue occurs due to the software's failure to properly neutralize special elements in SQL commands. The risk posed by this vulnerability includes data theft and unauthorized system access. Users are advised to update their MindValley Super PageMash installations to the latest, secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share