PT-2025-36543 · Uverif · Uverif

·

CVE-2025-10121

·

Published

2025-09-09

·

Updated

2025-09-09

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: uverif versions prior to 3.3
Description: A flaw has been found in uverif that allows for SQL injection. The issue is located in the addbatch function within the /admin/kami list file. Manipulation of the note argument can trigger the injection. This issue is potentially exploitable remotely.
Recommendations: As a temporary workaround, consider restricting access to the /admin/kami list file. Avoid using the note parameter in the addbatch function until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10121

Affected Products

Uverif