CVE 10 CRITICAL

SQL Injection Vulnerability in Explorance Blue_CVE-2025-57792

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database queries. The issue is exploitable without authentication, significantly raising the risk.

Basic Information

ID CVE-2025-57792
Source Mandiant
Published Jan 28, 2026 at 17:26
Modified Jan 28, 2026 at 18:36

Affected Product

Vendor Explorance
Product Blue
Affected Versions Explorance Blue 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.