Official Product Homepageproduct
http://ourenergy.se/ CVE-2018-25379
HIGH
Collectric CMU 1.0 SQL Injection via lang Parameter
Record summary
CVE-2018-25379 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Collectric CMUBrowse Ourenergy / Collectric CMU | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCollectric CMU 1.0 - 'lang' Hard-Coded Credentials / SQL injectionExploitDB exploitby Simon BrannstromNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25379 ExploitDB-45446exploit
https://www.exploit-db.com/exploits/45446 VulnCheck Advisory: Collectric CMU 1.0 SQL Injection via lang ParameterThird-party advisory
https://www.vulncheck.com/advisories/collectric-cmu-sql-injection-via-lang-parameter