SQL Injection via POST Requests Allowing Configuration Database Manipulation
Vulnerability Description
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41678
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- F. Bruckmoser, M. Eder, J. Heigl, M. Heudorn, G. Hofmarcher, M. Kadlec, M. Pristauz-Telsnigg, S. Resch, P. Schweinzer, M. Gschiel from St. Poelten UAS
More from MB connect line
View All →Affected Vendor
MB connect line
View all reports →