CVE-2025-2812

CRITICAL

Mydata Ticket Sales Automation < 2025-04-03 - SQL Injection

Title source: rule

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).

Exploits (1)

nomisec WORKING POC
by sahici · poc
https://github.com/sahici/CVE-2025-2812

Scores

CVSS v3 9.8
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
mydata/ticket_sales_automation < 2025-04-03
Published May 02, 2025
Tracked Since Feb 18, 2026