Description
FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26442 | FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries. |
References
History
Fri, 05 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shaneisrael
Shaneisrael fireshare |
|
| CPEs | cpe:2.3:a:shaneisrael:fireshare:1.2.25:*:*:*:*:*:*:* | |
| Vendors & Products |
Shaneisrael
Shaneisrael fireshare |
Tue, 02 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 02 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-02T19:48:50.800Z
Reserved: 2025-08-13T00:00:00.000Z
Link: CVE-2025-55476
Updated: 2025-09-02T19:48:28.532Z
Status : Analyzed
Published: 2025-09-02T18:15:35.783
Modified: 2025-09-05T18:10:09.907
Link: CVE-2025-55476
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD