Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 09.07.2025
affected
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 09.07.2025
Credits
Hasan Yasin Yasar
Yusuf Melih Daskiran
References
www.usom.gov.tr/bildirim/tr-25-0180
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.