CVE-2025-6918

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection. This issue affects Virtual PBX Software: before 09.07.2025.
Configurations

No configuration.

History

05 Jun 2026, 15:16

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection. This issue affects Virtual PBX Software: before 09.07.2025.
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0180 -

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('SQL Injection') en Ncvav Virtual PBX Software permite la inyección SQL. Este problema afecta a Virtual PBX Software: antes del 09.07.2025.

28 Jul 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-28 11:15

Updated : 2026-06-05 15:16


NVD link : CVE-2025-6918

Mitre link : CVE-2025-6918

CVE.ORG link : CVE-2025-6918


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')