First published: Mon Feb 10 2025(Updated: )
A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login. The manipulation of the argument usuario leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pixsoft Vivaz |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1156 is classified as a critical vulnerability.
CVE-2025-1156 is a SQL injection vulnerability affecting Pix Software Vivaz.
CVE-2025-1156 can be exploited remotely through manipulation of the 'usuario' argument in the login servlet.
Exploitation of CVE-2025-1156 can lead to unauthorized access to the database and potential data breaches.
To fix CVE-2025-1156, it is recommended to sanitize and validate user inputs to prevent SQL injection.