CVE-2025-57793

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.
Configurations

Configuration 1 (hide)

cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:43

Type Values Removed Values Added
Summary
  • (es) Las versiones de Explorance Blue anteriores a la 8.14.9 contienen una vulnerabilidad de inyección SQL causada por una validación insuficiente de la entrada proporcionada por el usuario en un componente de aplicación web. La entrada manipulada puede ejecutarse como parte de las consultas de la base de datos de backend. El problema es explotable sin autenticación, elevando significativamente el riesgo.

05 Feb 2026, 17:00

Type Values Removed Values Added
References () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0002.md - () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0002.md - Third Party Advisory
References () https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) - () https://online-help.explorance.com/blue/articles/security-advisories-(january-2026) - Vendor Advisory
References () https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57793 - () https://online-help.explorance.com/blue/articles/security-advisory:-cve-2025-57793 - Vendor Advisory
References () https://www.explorance.com/products/blue - () https://www.explorance.com/products/blue - Product
First Time Explorance
Explorance blue
CPE cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*

28 Jan 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6

28 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 18:16

Updated : 2026-06-17 09:43


NVD link : CVE-2025-57793

Mitre link : CVE-2025-57793

CVE.ORG link : CVE-2025-57793


JSON object : View

Products Affected

explorance

  • blue
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')