CVE-2025-67081

MEDIUM

itflow < 25.06 - Authenticated SQL Injection via Role ID Parameter

Title source: llm
STIX 2.1

Description

An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a profile. An attacker with admin account can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database. The vulnerability arises from insufficient sanitizing on integer parameter.

References (2)

Core 2

Scores

CVSS v3 4.9
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
itflow/itflow < 25.06
Published Jan 15, 2026
Tracked Since Feb 18, 2026