Home

Description

Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.

PUBLISHED Reserved 2025-01-17 | Published 2025-06-29 | Updated 2025-06-30 | Assigner hackerone




CRITICAL: 9.9CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Product status

Default status
unaffected

2.4.211 (semver) before 2.4.211
affected

References

community.ui.com/...048/af007d99-bb6d-4368-a12f-75e84de19e8d

cve.org (CVE-2025-24290)

nvd.nist.gov (CVE-2025-24290)

Download JSON