9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using the ‘buscame’ parameter in ‘/catalogo_c/catalogo.php’.
AI Analysis
SQL injection vulnerability allowing unauthorized database access
Basic Information
ID
CVE-2025-41009
Source
INCIBE
Published
Oct 27, 2025 at 11:35
Modified
Oct 27, 2025 at 13:17
Affected Product
Vendor
Disenno de Recursos Educativos S.L
Product
virtual campus platform
Version
all versions
Affected Versions
Disenno de Recursos Educativos S.L virtual campus platform all versions
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Disenno de Recursos Educativos S.L
Product
virtual campus platform
Version
all versions