CVE-2025-25151

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 89

Summary

CVE-2025-25151 is a severe SQL Injection vulnerability affecting the uListing application from versions n/a through 2.1.6. An attacker can exploit this vulnerability by injecting malicious SQL commands into input fields, leading to unauthorized access, data theft, or even system compromise. The vulnerability arises due to the application's failure to neutralize special elements properly, putting thousands of users at risk. Organizations utilizing this software are urged to update to the latest version or apply appropriate security patches to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share