NONE · 0

CVE-2025-2200

SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on ...

Vulnerability Description

SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-2200?

CVE-2025-2200 is a documented vulnerability. SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on ...

How severe is CVE-2025-2200?

CVSS scoring is not yet available for CVE-2025-2200. Check NVD for updates.

Is there a patch for CVE-2025-2200?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.