CVE-2025-24728
CVSS 3.1 Score 8.5 of 10 (high)
Details
Summary
CVE-2025-24728 is an SQL injection vulnerability affecting Yannick Lefebvre Bug Library. The flaw, which allows blind SQL injection, permits unauthorized users to inject malicious SQL commands into the application. This vulnerability exists due to improper neutralization of special elements used in SQL commands. The issue affects versions of Bug Library from n/a through 2.1.4. Successful exploitation could result in unauthorized access to sensitive data or even complete system takeover. Users are advised to upgrade to a patched version of the software to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.