An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-core system has a limited SQL injection vulnerability, which may lead to partial data leakage or disruption of normal system operations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ryansu
Ryansu simple Admin
CPEs cpe:2.3:a:ryansu:simple_admin:*:*:*:*:*:*:*:*
Vendors & Products Ryansu
Ryansu simple Admin

Wed, 27 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 17:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-core system has a limited SQL injection vulnerability, which may lead to partial data leakage or disruption of normal system operations.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-27T17:46:49.476Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51667

cve-icon Vulnrichment

Updated: 2025-08-27T17:45:31.725Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-27T18:15:46.003

Modified: 2025-09-09T15:46:50.510

Link: CVE-2025-51667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.