CVE-2018-25161 is an SQL injection vulnerability in Warranty Tracking System version 11.06.3, specifically within the SearchCustomer.php component. Attackers can exploit this by injecting malicious SQL code into the txtCustomerCode, txtCustomerName, and txtPhone POST parameters to execute arbitrary database queries. This vulnerability has a high CVSS score of 8.2, indicating it can be exploited remotely with low complexity to achieve high confidentiality impact (e.g., extracting sensitive data like usernames and database details) and low integrity impact. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the nature of SQL injection makes it a persistent threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Warrantytrack | Warranty Tracking System | 11.06.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.