Description
While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. Version 5.20 of MegaBIP fixes this issue.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version
Credits
Kamil Szczurowski
Robert Kruczek
References
cert.pl/en/posts/2025/05/CVE-2025-3893
megabip.pl/index.php?id=24,145
www.gov.pl/...twa-dotyczaca-biuletynow-informacji-publicznej