CVE 9.3 CRITICAL

SQL injection on the virtual campus platform of Diseño de Recursos Educativos_CVE-2025-41009

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using the ‘buscame’ parameter in ‘/catalogo_c/catalogo.php’.

AI Analysis

SQL injection vulnerability allowing unauthorized database access

Basic Information

ID CVE-2025-41009
Source INCIBE
Published Oct 27, 2025 at 11:35
Modified Oct 27, 2025 at 13:17

Affected Product

Vendor Disenno de Recursos Educativos S.L
Product virtual campus platform
Version all versions
Affected Versions Disenno de Recursos Educativos S.L virtual campus platform all versions

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Disenno de Recursos Educativos S.L
Product virtual campus platform
Version all versions

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.