CVE-2025-39566

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 16, 2025
CWE ID 89

Summary

CVE-2025-39566 is a vulnerability affecting the Bob Hostel software from versions n/a through 1.1.5.6. This issue involves an SQL Injection flaw where special elements in SQL commands are not properly neutralized. As a result, attackers can carry out Blind SQL Injection attacks, gaining unauthorized access to sensitive data without the need for user input or explicit command execution. This vulnerability poses a significant security risk and requires immediate attention and patching from users of the Bob Hostel software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share