Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, asociar_documentos/asociar_borrar_referencia.php radi_nume, asociar_documentos/asociar_documento_buscar_query.php radi_nume, asociar_documentos/asociar_documento_grabar.php txt_radi_nume, asociar_documentos/asociar_documento radi_nume, radicacion/buscar_usuario.php buscar_tipo, radicacion/formArea_ajax.php codDepe, radicacion/formDepeHijo_ajax.php codDepe, radicacion/formDepePadre_ajax.php codInst, radicacion/ver_datos_usuario.php destinatorio, reportes/reporte_TraspasoDocFisico.php verrad, tx/datos_imprimir_sobre.php txt_usua_codi, tx/datos_imprimir_sobre.php nume_radi_temp, tx/revertir_firma_digital_grabar.php txt_radi_nume, tx/tx_borrar_opcion_imp.php codigo_opc, tx/tx_realizar_tx.php txt_radicados, tx/tx_seguridad_documentos.php txt_radicados, or uploadFiles/cargar_doc_digitalizado_paginador.php txt_depe_codi.
References
| Link | Resource |
|---|---|
| https://minka.gob.ec/quipux-comunitario/quipux-comunitario | Permissions Required |
| https://seguridaddigital.ec/research/20251101/report-20251101.en.pdf | Third Party Advisory |
Configurations
History
09 Jan 2026, 18:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://seguridaddigital.ec/research/20251101/report-20251101.en.pdf - Third Party Advisory |
09 Jan 2026, 18:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Quipux quipux
Quipux |
|
| References | () https://minka.gob.ec/quipux-comunitario/quipux-comunitario - Permissions Required | |
| References | () https://seguridaddigital.ec/research/20251101/report-20251101.en.pdf - Broken Link | |
| CPE | cpe:2.3:a:quipux:quipux:4.0.1:*:*:*:*:*:*:* |
05 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 CWE-74 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
05 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 19:16
Updated : 2026-01-09 18:52
NVD link : CVE-2025-55343
Mitre link : CVE-2025-55343
CVE.ORG link : CVE-2025-55343
JSON object : View
Products Affected
quipux
- quipux
