CVE-2025-4650: User with high privileges is able to introduce a SQLi using the Meta Service indicator page
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used in an SQL Command.This issue affects web: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4650?
CVE-2025-4650 is categorized as a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-4650?
To fix CVE-2025-4650, upgrade to versions 24.10.9, 24.04.16, or 23.10.26 or later of the affected software.
What type of vulnerability is CVE-2025-4650?
CVE-2025-4650 is an SQL injection vulnerability caused by improper neutralization of special elements in SQL commands.
Which versions are affected by CVE-2025-4650?
CVE-2025-4650 affects versions from 24.10.0 to before 24.10.9, 24.04.0 to before 24.04.16, and 23.10.0 to before 23.10.26.
Who is at risk from CVE-2025-4650?
Users with high privileges are at risk from CVE-2025-4650, as they can potentially exploit the vulnerability.