VYPR

SD.NET RIM

by Sitzungsdienst

CVEs (1)

  • CVE-2019-25359HigFeb 18, 2026
    risk 0.53cvss 8.2epss 0.00

    SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure.