Description

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

INFO

Published Date :

2025-05-23T10:20:02.391Z

Last Modified :

2025-05-23T12:13:22.569Z

Source :

CERT-PL
AFFECTED PRODUCTS

The following products are affected by CVE-2025-3893 vulnerability.

Vendors Products
Jan Syski
  • Megabip

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability