NONE · 0

CVE-2025-41009

SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using th...

Vulnerability Description

SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using the ‘buscame’ parameter in ‘/catalogo_c/catalogo.php’.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-41009?

CVE-2025-41009 is a documented vulnerability. SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using th...

How severe is CVE-2025-41009?

CVSS scoring is not yet available for CVE-2025-41009. Check NVD for updates.

Is there a patch for CVE-2025-41009?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.