Description

FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries.

INFO

Published Date :

2025-09-02T00:00:00.000Z

Last Modified :

2025-09-02T19:48:50.800Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-55476 vulnerability.

Vendors Products
Shaneisrael
  • Fireshare

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact