Skip to main content

CVE-2025-8162: SQL Injection in deerwms deer-wms-2

Medium
VulnerabilityCVE-2025-8162cvecve-2025-8162
Published: Fri Jul 25 2025 (07/25/2025, 17:02:11 UTC)
Source: CVE Database V5
Vendor/Project: deerwms
Product: deer-wms-2

Description

A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issue is some unknown functionality of the file /system/dept/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Technical Details

Data Version
5.1
Assigner Short Name
VulDB
Date Reserved
2025-07-25T07:00:23.484Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6883bc39ad5a09ad00539a2b

Added to database: 7/25/2025, 5:17:45 PM

Last updated: 7/25/2025, 5:17:45 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats