CVE-2019-25299

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can exploit time-based and boolean-based blind SQL injection techniques to extract information or potentially interact with the underlying database.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) RimbaLinux AhadPOS 1.11 contiene una vulnerabilidad de inyección SQL en el parámetro 'alamatCustomer' que permite a los atacantes manipular consultas de base de datos a través de solicitudes POST manipuladas. Los atacantes pueden explotar técnicas de inyección SQL ciega basada en tiempo y basada en booleanos para extraer información o potencialmente interactuar con la base de datos subyacente.

06 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 17:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25299

Mitre link : CVE-2019-25299

CVE.ORG link : CVE-2019-25299


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')