cve/2025/CVE-2025-53122.md
2025-09-29 21:09:30 +02:00

1.4 KiB

CVE-2025-53122

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. Usersshould upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian andHorizon installation instructions state that they are intended for installationwithin an organization's private networks and should not be directly accessiblefrom the Internet.

POC

Reference

Github

No PoCs found on GitHub currently.