CNNVD-202511-2934 Information

CNNVD ID

CNNVD-202511-2934

CVE-2025-13757

  • CNNVD Published: 2025-11-27

Description (Chinese)

Devolutions Server是加拿大Devolutions公司的一个应用系统。提供功能齐全的共享帐户和密码管理解决方案。 Devolutions Server 2025.2.20及之前版本和2025.3.8及之前版本存在安全漏洞,该漏洞源于使用日志中容易受到SQL注入攻击。

Description (English)

The Defenses Server is an application of the Canadian Defenses Corporation. Provide a fully functional shared account and password management solution. There is a security loophole in the use logs of Devlutions Server 2025.2.20 and previous and previous versions 2025.3.8 and earlier, which stems from the vulnerability to SQL injections.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Devolutions

Published

2025-11-27

Last Modified

2026-02-24

References

https://devolutions.net/security/advisories/DEVO-2025-0018/ https://access.redhat.com/security/cve/cve-2025-13757

Patch

https://devolutions.net/security/advisories/DEVO-2025-0018/

Share on: