First published: Fri Jan 24 2025(Updated: )
A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. It has been classified as critical. Affected is an unknown function of the file /admin/sys/menu/list. The manipulation of the argument sort/order leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
JoeyBling bootplus | <=247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-0698 is classified as critical.
To fix CVE-2025-0698, update to a version of JoeyBling bootplus that is not affected by this vulnerability.
CVE-2025-0698 is a SQL injection vulnerability.
CVE-2025-0698 affects an unknown function of the file /admin/sys/menu/list.
If exploited, CVE-2025-0698 can lead to unauthorized access to the database.