mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
22 lines
1.4 KiB
Markdown
22 lines
1.4 KiB
Markdown
|
|
### [CVE-2025-53122](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53122)
|
|||
|
|

|
|||
|
|

|
|||
|
|

|
|||
|
|

|
|||
|
|

|
|||
|
|

|
|||
|
|
&color=brightgreen)
|
|||
|
|
|
|||
|
|
### Description
|
|||
|
|
|
|||
|
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. Usersshould upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian andHorizon installation instructions state that they are intended for installationwithin an organization's private networks and should not be directly accessiblefrom the Internet.
|
|||
|
|
|
|||
|
|
### POC
|
|||
|
|
|
|||
|
|
#### Reference
|
|||
|
|
- https://docs.opennms.com/meridian/2024/releasenotes/changelog.html#releasenotes-changelog-Meridian-2024.2.6
|
|||
|
|
|
|||
|
|
#### Github
|
|||
|
|
No PoCs found on GitHub currently.
|
|||
|
|
|