cvedb.io
CVE-2018-25379
HIGH · CVSS 8.2
EPSS exploitation probability: 0%
Published 2026-05-25T15:16:21.050 · Last modified 2026-07-24T10:10:00.197

Summary

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.