We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. Version 5.20 of MegaBIP fixes this issue.
Reserved 2025-04-23 | Published 2025-05-23 | Updated 2025-05-23 | Assigner CERT-PLCWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Kamil Szczurowski
Robert Kruczek
cert.pl/en/posts/2025/05/CVE-2025-3893
megabip.pl/index.php?id=24,145
www.gov.pl/...twa-dotyczaca-biuletynow-informacji-publicznej
Support options