CVE-2025-40885: Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0
A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40885?
CVE-2025-40885 is considered a high severity vulnerability due to its potential for SQL Injection attacks.
How do I fix CVE-2025-40885?
To fix CVE-2025-40885, ensure proper input validation and parameterized queries are implemented in the Smart Polling functionality.
Who is affected by CVE-2025-40885?
CVE-2025-40885 affects users of Guardian CMC versions prior to 25.2.0 that utilize the Smart Polling feature.
What types of attacks can CVE-2025-40885 facilitate?
CVE-2025-40885 can facilitate unauthorized execution of arbitrary SELECT SQL statements on the database.
Is authentication required for exploiting CVE-2025-40885?
Yes, an authenticated user with limited privileges can exploit CVE-2025-40885.