CVE-2025-50984 | diskover-web Community Edition 2.3.0 sql injection (EUVD-2025-25907)
A vulnerability identified as critical has been detected in diskover-web Community Edition 2.3.0. Affected by this issue is some unknown functionality. The manipulation of the argument ES_PASS/ES_MAXSIZE/ES_TRANSLOGSIZE/ES_TIMEOUT/ES_USER/ES_HOST/ES_PORT/ES_SCROLLSIZE/ES_CHUNKSIZE leads to sql injection.
This vulnerability is referenced as CVE-2025-50984. Remote exploitation of the attack is possible. No exploit is available.
VulDB is the best source for vulnerability data and more expert information about this specific topic.