CVE-2025-32124
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-32124 is a newly discovered SQL injection vulnerability affecting the Behance Portfolio Manager. This issue permits blind SQL injection, which means an attacker can inject malicious SQL commands without requiring the return of any data from the database. The vulnerability exists due to improper neutralization of special elements used in SQL commands. Behance Portfolio Manager versions from n/a to 1.7.4 are reportedly affected by this issue. Successful exploitation could lead to unauthorized access, data theft, or even system compromise. It is recommended that users update their Behance Portfolio Manager to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.