CVE-2025-13485

🟡 Monitoruj

Wstrzyknięcie SQL w itsourcecode Online File Management System umożliwia zdalne ataki.

CVSS
7.3
EPSS
0.4%
Exploit
none
Vendor
admerc
Opis źródłowy (NVD)

A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-11-21 00:15:49 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje