216.73.216.133

CVE-2019-25359

· Published 18/02/2026 22:16 · Modified 19/02/2026 15:53

Labels: CVE-2019-25359 2026-02-18CVE-2019-25359CWE-352[email protected]

Essential information

Published
18/02/2026 22:16
Modified
19/02/2026 15:53
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sd.net / rim cpe:2.3:a:sd.net:rim:*:*:*:*:*:*:*:*

References