CVE-2025-28009
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 23, 2025
CWE ID 89
Summary
CVE-2025-28009 is a SQL injection vulnerability that affects Dietiqa App version 1.0.20. The issue lies in the `u` parameter of the progress-body-weight.php endpoint, which allows an attacker to inject malicious SQL code and potentially gain unauthorized access to sensitive data. This vulnerability can lead to data leakage or even complete system compromise. It is essential for users to apply the necessary patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- App!