CVE-2025-40888: Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0
A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40888?
CVE-2025-40888 has a high severity level due to its potential for unauthorized data access through SQL Injection.
How does CVE-2025-40888 occur?
CVE-2025-40888 occurs due to improper validation of an input parameter within the CLI functionality of Guardian CMC.
Who is impacted by CVE-2025-40888?
CVE-2025-40888 impacts authenticated users with limited privileges in Guardian CMC versions up to 25.3.0.
How can I fix CVE-2025-40888?
To fix CVE-2025-40888, update Guardian CMC to a version that properly validates input parameters to prevent SQL Injection.
What are the potential consequences of CVE-2025-40888?
The potential consequences of CVE-2025-40888 include arbitrary execution of SQL statements, leading to unauthorized data exposure in the database.