{ "id": "CVE-2024-25525", "sourceIdentifier": "cve@mitre.org", "published": "2024-05-08T15:15:08.310", "lastModified": "2024-05-08T15:15:08.310", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx." } ], "metrics": {}, "references": [ { "url": "https://gist.github.com/Mr-xn/bc8261a5c3e35a72768723acf1da358d#officefiledownloadaspx", "source": "cve@mitre.org" } ] }