Home

Description

owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.

PUBLISHED Reserved 2025-03-11 | Published 2025-05-13 | Updated 2025-05-14 | Assigner mitre

References

github.com/slowlyo/owl-admin/issues/182

gist.github.com/LTLTLXEY/8f8ea23290f45fbc5cb2191a39cc74e8

cve.org (CVE-2025-28057)

nvd.nist.gov (CVE-2025-28057)

Download JSON