CVE-2025-67811 is a medium-severity SQL injection vulnerability affecting Area9 Rhapsode versions 1.47.3 and earlier. Authenticated attackers can exploit multiple API endpoints due to insufficient input validation, allowing them to execute arbitrary SQL commands. This could lead to unauthorized access to sensitive database information. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability has a CVSS score of 6.5 and a FAUCET Risk Score of 85/100, indicating a notable potential impact. The issue has been patched in version 1.47.4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.47.3CPE matchmatch criteria | cpe:2.3:a:area9lyceum:rhapsode:1.47.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.