Skip to content

Advantech SaaS Composer - SQL Injection - CVE-2025-52694#14825

Merged
Akokonunes merged 3 commits intoprojectdiscovery:mainfrom
Winz18:add-cve-2025-52694
Jan 22, 2026
Merged

Advantech SaaS Composer - SQL Injection - CVE-2025-52694#14825
Akokonunes merged 3 commits intoprojectdiscovery:mainfrom
Winz18:add-cve-2025-52694

Conversation

@Winz18
Copy link
Copy Markdown
Contributor

@Winz18 Winz18 commented Jan 12, 2026

PR Information

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)

Additional Details

Fofa Query: title="SaaS Composer"

  • Template Validation: The template has been validated using nuclei -validate and passed successfully.
  • Scan Result: Tested against a target environment. The injection was confirmed with a time delay of ~6 seconds as expected.

Screenshots:
image
Screenshot 2026-01-12 230304

@theamanrawat theamanrawat added the Done Ready to merge label Jan 22, 2026
@Akokonunes Akokonunes merged commit 9f7b04a into projectdiscovery:main Jan 22, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Done Ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants