CVE-2025-4688

CRITICAL

BGS Interactive SINAV.LINK <1.2 - SQL Injection

Title source: llm

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects SINAV.LINK Exam Result Module: before 1.2.

Exploits (1)

nomisec STUB
by sahici · poc
https://github.com/sahici/CVE-2025-4688

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
BGS Interactive/SINAV.LINK Exam Result Module < 1.2
Published Sep 16, 2025
Tracked Since Feb 18, 2026