Description
Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
7.0.0.0 (semver)
8.0.0.0 (semver)
Credits
Maksymilian Kubiak, Sławomir Zakrzewski, Jakub Stankiewicz - Afine Team
References
cert.pl/posts/2025/04/CVE-2025-1980
cert.pl/en/posts/2025/04/CVE-2025-1980
ready-os.com/pl/