CVE-2025-8220

HIGH

Engeman Web < 12.0.0.1 - SQL Injection via LanguageCombobox Cookie Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-8220. PoCs published by m3m0o.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-8220, an unauthenticated SQL injection vulnerability in Engeman Web <= 12.0.0.2. It includes step-by-step exploitation guidance, proof-of-concept payloads, and a custom tamper script for sqlmap to bypass application-specific restrictions.

Description

A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /Login/RecoveryPass of the component Password Recovery Page. The manipulation of the argument LanguageCombobox as part of Cookie leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 12.0.0.3 is sufficient to fix this issue. Upgrading the affected component is advised. The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

nomisec WRITEUP 3 stars
by m3m0o · poc
https://github.com/m3m0o/engeman-web-language-combobox-sqli

This repository provides a detailed technical analysis of CVE-2025-8220, an unauthenticated SQL injection vulnerability in Engeman Web <= 12.0.0.2. It includes step-by-step exploitation guidance, proof-of-concept payloads, and a custom tamper script for sqlmap to bypass application-specific restrictions.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Engeman Web <= 12.0.0.2
No auth needed
Prerequisites: Access to the password recovery page · Ability to modify the LanguageCombobox cookie
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.317808
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.317808
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.616747
Exploit, Third Party Advisory exploit
https://github.com/m3m0o/engeman-web-language-combobox-sqli

Scores

CVSS v3 7.3
EPSS 0.0056
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
engeman/web < 12.0.0.1
Published Jul 27, 2025
Tracked Since Feb 18, 2026