We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-52924



Description

In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.

Reserved 2025-06-22 | Published 2025-07-19 | Updated 2025-07-19 | Assigner mitre


MEDIUM: 4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 2025.2.0
affected

References

oneidentity.com

onelogin.service-now.com/...a0d76d70db185340d5505eea4b96199f

cve.org (CVE-2025-52924)

nvd.nist.gov (CVE-2025-52924)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-52924

Support options

Helpdesk Chat, Email, Knowledgebase