Back to search
CVE-2025-3893
Published: May 23, 2025
Modified: May 23, 2025
PUBLISHED
Description
While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability. Version 5.20 of MegaBIP fixes this issue.
| Vendor | Product | Versions |
|---|---|---|
Jan Syski | MegaBIP | affected 0 - <= 5.19 |
Weaknesses (CWE)
References
https://cert.pl/en/posts/2025/05/CVE-2025-3893
third-party-advisory
https://megabip.pl/index.php?id=24,145
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now