Home

Description

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.

PUBLISHED Reserved 2025-08-19 | Published 2026-01-28 | Updated 2026-01-28 | Assigner Mandiant

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 8.14.9
affected

Credits

Abdulrahman Nour, Mandiant finder

Abdulrahman Nour, Mandiant reporter

References

www.explorance.com/products/blue product

online-help.explorance.com/...rity-advisories-(january-2026) vendor-advisory

online-help.explorance.com/...urity-advisory:-cve-2025-57793 vendor-advisory

github.com/...Disclosures/blob/master/2026/MNDT-2026-0002.md third-party-advisory

cve.org (CVE-2025-57793)

nvd.nist.gov (CVE-2025-57793)

Download JSON