CVE-2025-67102

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.
Configurations

No configuration.

History

11 Mar 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
CWE CWE-89

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL en la funcionalidad alldayoffs de Jorani hasta la v1.0.4, permite a un atacante autenticado ejecutar comandos SQL arbitrarios a través del parámetro entity.

17 Feb 2026, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 20:22

Updated : 2026-03-11 16:16


NVD link : CVE-2025-67102

Mitre link : CVE-2025-67102

CVE.ORG link : CVE-2025-67102


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')