9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.
Basic Information
ID
CVE-2025-6918
Source
TR-CERT
Published
Jul 28, 2025 at 11:05
Modified
Jul 28, 2025 at 14:32
Affected Product
Vendor
Ncvav
Product
Virtual PBX Software
Affected Versions
Ncvav Virtual PBX Software 0