10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database queries. The issue is exploitable without authentication, significantly raising the risk.
Basic Information
ID
CVE-2025-57792
Source
Mandiant
Published
Jan 28, 2026 at 17:26
Modified
Jan 28, 2026 at 18:36
Affected Product
Vendor
Explorance
Product
Blue
Affected Versions
Explorance Blue 0