Description
In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 2024.MS4
Credits
Maciej Kazulak
References
cert.pl/en/posts/2025/08/CVE-2025-2313/