CVE-2025-32993

medium

Description

Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.

References

https://www.visionhelpdesk.com/vision-helpdesk-v5-7-0-stable-version-released.html

https://nav1n.medium.com/sql-injection-in-vision-helpdesk-tools-a83dfc27f3ab

Details

Source: Mitre, NVD

Published: 2025-04-15

Updated: 2025-04-15

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00052