What is CVE-2026-25405?
CVE-2026-25405 is an SQL Injection vulnerability in eRoom versions <= 1.7.1 that can be exploited by users with the Contributor role. This flaw may allow unauthorized database access, so upgrading to the latest version immediately is strongly recommended.
Azərbaycanca: CVE-2026-25405, eRoom-un 1.7.1 və daha əvvəlki versiyalarında Contributor rolunda olan istifadəçilər tərəfindən SQL Injection hücumuna imkan verən boşluqdur. Bu zəiflik verilənlər bazasına icazəsiz girişə səbəb ola bilər, ona görə də dərhal proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of eRoom are affected by CVE-2026-25405?
This SQL Injection vulnerability affects eRoom versions 1.7.1 and earlier.
What privileges does an attacker need to exploit CVE-2026-25405?
An attacker must have the Contributor role in the eRoom system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.