HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2018-25379 — Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in...

·Source: NIST NVD

Updated:

Executive Summary

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.

Analysis

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques. CVSS Score: 8.2. Published: 2026-05-25T15:16:21.050.

Indicators of Compromise (1)

CVE (1)
CVE-2018-25379
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats