CVE-2025-2353
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 17, 2025
CWE ID 862
Summary
CVE-2025-2353 is a critical vulnerability affecting VAM Virtual Airlines Manager up to version 2.6.2. The issue lies within the HTTP GET Parameter Handler's unknown function in the /vam/index.php file. Manipulation of the ID/registry_id/plane_icao arguments facilitates SQL injection, allowing remote attackers to launch attacks. The exploit for this vulnerability has been disclosed publicly, increasing the risk for potential exploitation. Other parameters may also be susceptible to this issue. Despite early notification to the vendor, they have yet to respond.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.