CVE-2025-39566
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Apr 16, 2025
CWE ID 89
Summary
CVE-2025-39566 is a vulnerability affecting the Bob Hostel software from versions n/a through 1.1.5.6. This issue involves an SQL Injection flaw where special elements in SQL commands are not properly neutralized. As a result, attackers can carry out Blind SQL Injection attacks, gaining unauthorized access to sensitive data without the need for user input or explicit command execution. This vulnerability poses a significant security risk and requires immediate attention and patching from users of the Bob Hostel software.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress