SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sitzungsdienst
Sitzungsdienst sd.net Rim |
|
| Vendors & Products |
Sitzungsdienst
Sitzungsdienst sd.net Rim |
Wed, 18 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure. | |
| Title | SD.NET RIM 4.7.3c - 'idtyp' SQL Injection | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-18T21:55:05.859Z
Updated: 2026-02-18T21:55:05.859Z
Reserved: 2026-02-13T17:37:10.778Z
Link: CVE-2019-25359
No data.
Status : Received
Published: 2026-02-18T22:16:21.357
Modified: 2026-02-18T22:16:21.357
Link: CVE-2019-25359
No data.