Vulnerability Description
Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab
- https://www.visionhelpdesk.com/vision-helpdesk-v5-7-0-stable-version-released.ht
- https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab
FAQ
What is CVE-2025-32993?
CVE-2025-32993 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.
How severe is CVE-2025-32993?
CVE-2025-32993 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32993?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.