CVE-2025-67081 is an SQL injection vulnerability affecting Itflow versions up to 25.06, specifically within the "role_id" parameter during profile editing. An authenticated administrator can exploit this flaw to perform blind SQL injection, enabling the extraction of sensitive data from the database. Rated as Medium severity (CVSS 4.9), this vulnerability requires high privileges (admin account) but has low attack complexity and no user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.06CPE matchmatch criteria | cpe:2.3:a:itflow:itflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.