SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.
Fixes

Solution

Innovación y Cualificación has released a new version that fixes the vulnerabilities detected in the affected plugins. It has been implemented in all installations of the affected software, and the process will be completed in December 2024.


Workaround

No workaround given by the vendor.

History

Tue, 18 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description QL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php. SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.

Mon, 17 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 10:30:00 +0000

Type Values Removed Values Added
Description QL injection vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php. QL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.
Title SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php SQL injection vulnerability in the Innovación y Cualificación IcProgreso plugin

Mon, 17 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description QL injection vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.
Title SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-18T15:48:51.594Z

Reserved: 2025-03-11T09:52:08.670Z

Link: CVE-2025-2200

cve-icon Vulnrichment

Updated: 2025-03-17T12:22:40.415Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-17T10:15:16.400

Modified: 2025-03-18T16:15:28.347

Link: CVE-2025-2200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.