CNNVD-202602-455 Information

CNNVD ID

CNNVD-202602-455

CVE-2026-1432

  • CNNVD Published: 2026-02-03

Description (Chinese)

Buroweb是法国Buroweb公司的一个电商平台。 Buroweb 2505.0.12版本存在SQL注入漏洞,该漏洞源于tablon组件中对用户输入清理不当,可能导致攻击者执行数据库查询并访问机密信息。

Description (English)

Buroweb is an electrician platform of the French company Buroweb. The version of Buroweb 2505.0.12 contains an injection loophole in SQL, which stems from the inappropriate clean-up of user input in the tablon component, which may result in the attackers performing database searches and accessing confidential information.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

Buroweb

Published

2026-02-03

Last Modified

2026-02-24

References

https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-sqli-buroweb-platform

Patch

https://www.t-systems.com/de/en

Share on: