CVE-2025-13319

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input. The API is not enabled by default, and a valid API token is required to perform the attack.
Configurations

No configuration.

History

17 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-17 17:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-13319

Mitre link : CVE-2025-13319

CVE.ORG link : CVE-2025-13319


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')