216.73.217.22

CVE-2018-25339

· Published 17/05/2026 13:16 · Modified 18/05/2026 17:32

Labels: CVE-2018-25339 2026-05-17CVE-2018-25339CWE-89[email protected]

Essential information

Published
17/05/2026 13:16
Modified
18/05/2026 17:32
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extract data.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
zechat / zechat cpe:2.3:a:zechat:zechat:1.5:*:*:*:*:*:*:*

References