This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 25 Sep 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue. | |
Title | Authenticated Union based SQL-injection in the search input field | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: NCSC-NL
Published:
Updated: 2025-09-25T19:30:03.608Z
Reserved: 2025-09-22T10:23:28.574Z
Link: CVE-2025-59816

No data.

Status : Received
Published: 2025-09-25T20:15:35.647
Modified: 2025-09-25T20:15:35.647
Link: CVE-2025-59816

No data.

No data.