An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the database server banner and version, current database user and schema, the current DBMS user privileges, and arbitrary data from any table.
History

Mon, 25 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Yoosee
Yoosee yoosee
Vendors & Products Yoosee
Yoosee yoosee

Fri, 22 Aug 2025 18:00:00 +0000

Type Values Removed Values Added
Description An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful exploitation enables extraction of sensitive database information, including but not limited to, the database server banner and version, current database user and schema, the current DBMS user privileges, and arbitrary data from any table.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-22T00:00:00.000Z

Updated: 2025-08-22T17:55:37.780Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-52085

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-22T18:15:35.550

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-52085

cve-icon Redhat

No data.