Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15834 | An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication. |
Thu, 12 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsiqueue
Rsiqueue management System |
|
| CPEs | cpe:2.3:a:rsiqueue:management_system:3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Rsiqueue
Rsiqueue management System |
Tue, 20 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 20 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-20T15:32:56.530Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26086
Updated: 2025-05-20T15:04:09.133Z
Status : Analyzed
Published: 2025-05-20T15:16:07.023
Modified: 2025-06-12T16:20:56.180
Link: CVE-2025-26086
No data.
OpenCVE Enrichment
No data.
EUVD