VYPR
Unrated severityNVD Advisory· Published Jan 2, 2023· Updated Apr 10, 2025

82Flex WEIPDCRM sql injection

CVE-2015-10008

Description

UNSUPPORTED WHEN ASSIGNED A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is recommended to apply a patch to fix this issue. The identifier VDB-217185 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in 82Flex WEIPDCRM allows remote attackers to manipulate database queries via an unknown part; the product is end-of-life.

Vulnerability

The 82Flex WEIPDCRM software contains an SQL injection vulnerability in an unknown part. The manipulation leads to SQL injection, as described in the CVE description [1]. The software is end-of-life, no longer supported, and the repository was archived as read-only on July 13, 2022. The specific affected version is not clearly identified; the vulnerability was addressed in commit 43bad79392332fa39e31b95268e76fbda9fec3a4 [1].

Exploitation

An attacker can initiate the attack remotely without any prior authentication or user interaction, as stated in the CVE description. The exact parameters and vectors are not disclosed in the available references, but the vulnerability is classified as critical, suggesting low complexity of exploitation [1].

Impact

Successful exploitation allows an attacker to perform SQL injection, which can lead to unauthorized access to the database, information disclosure, and potential data manipulation. The impact is considered critical, and since the product is unsupported, no official fix or support is available.

Mitigation

No official patch is provided by the maintainer, as the product is unsupported. The repository is archived and read-only, meaning no further updates will be issued. The best mitigation is to upgrade to a supported solution or discontinue use of the software. The commit 43bad79392332fa39e31b95268e76fbda9fec3a4 was a hotfix applied before archival, but its content only addresses XSS filtering, not the SQL injection directly; the specific SQL injection fix may be incomplete or absent [1]. Users are recommended to apply the patch from that commit if possible, but reliance on unsupported software is strongly discouraged.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • 82Flex/WEIPDCRMllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: n/a

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.