Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16267 | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This vulnerability affects unknown code of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to sql injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Realcetecnologia
Realcetecnologia queue Ticket Kiosk |
|
| CPEs | cpe:2.3:a:realcetecnologia:queue_ticket_kiosk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Realcetecnologia
Realcetecnologia queue Ticket Kiosk |
Thu, 29 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This vulnerability affects unknown code of the file /adm/index.php of the component Admin Login Page. The manipulation of the argument Usuário leads to sql injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Realce Tecnologia Queue Ticket Kiosk Admin Login Page index.php sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-28T17:36:10.001Z
Reserved: 2025-05-25T17:14:23.635Z
Link: CVE-2025-5176
Updated: 2025-05-27T14:18:56.984Z
Status : Analyzed
Published: 2025-05-26T08:15:19.700
Modified: 2025-06-03T15:44:04.310
Link: CVE-2025-5176
No data.
OpenCVE Enrichment
No data.
EUVD