CVE-2025-26971
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Feb 25, 2025
CWE ID 89
Summary
CVE-2025-26971 is an SQL Injection vulnerability affecting the ays-pro Poll Maker from versions n/a through 5.6.5. An attacker can exploit this issue by neutralizing special elements in SQL commands improperly, allowing Blind SQL Injection. This vulnerability could potentially allow unauthorized access to sensitive data or even enable attackers to execute malicious SQL statements, potentially leading to significant data breaches or system compromises.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share