CVE-2025-67102: SQL Injection
A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67102?
CVE-2025-67102 has a high severity rating due to its potential for SQL injection, allowing attackers to execute arbitrary commands.
How do I fix CVE-2025-67102?
To fix CVE-2025-67102, upgrade Jorani to version 1.0.5 or later, where the vulnerability has been addressed.
Who is affected by CVE-2025-67102?
CVE-2025-67102 affects Jorani versions up to and including 1.0.4 for users utilizing the alldayoffs feature.
What kind of attacks can be performed using CVE-2025-67102?
An attacker can perform SQL injection by exploiting the entity parameter in the alldayoffs feature, potentially compromising the database.
Is authentication required to exploit CVE-2025-67102?
Yes, CVE-2025-67102 requires an authenticated user to exploit the SQL injection vulnerability.