CVE-2019-25348

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
12/02/2026
Last modified:
12/02/2026

Description

Computrols CBAS-Web 19.0.0 contains a boolean-based blind SQL injection vulnerability in the 'id' parameter that allows authenticated attackers to manipulate database queries. Attackers can exploit the vulnerability by crafting boolean-based SQL injection payloads in the 'id' parameter of the servers endpoint to extract or infer database information.