CVE-2026-1517 PUBLISHED

iomad Company Admin Block sql injection

Assigner: VulDB
Reserved: 28.01.2026 Published: 05.02.2026 Updated: 05.02.2026

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block. Such manipulation leads to sql injection. The attack can be executed remotely. Upgrading to version 4.5 LTS and 5.0 is able to address this issue. You should upgrade the affected component.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.1

Product Status

Vendor n/a
Product iomad
Versions
  • Version 3.1 is affected
  • Version 3.2 is affected
  • Version 3.3 is affected
  • Version 3.4 is affected
  • Version 3.5 is affected
  • Version 3.6 is affected
  • Version 3.7 is affected
  • Version 3.8 is affected
  • Version 3.9 is affected
  • Version 3.10 is affected
  • Version 3.11 is affected
  • Version 4.0 is affected
  • Version 4.1 is affected
  • Version 4.2 is affected
  • Version 4.3 is affected
  • Version 4.4 is affected
  • Version 4.5 is affected
  • Version 5.0 is affected
  • Version 4.5 LTS is unaffected
  • Version 5.0 is unaffected

Credits

  • Vaibhav Gupta (Appfend Technologies Limited) finder
  • VulDB GitHub Analyzer tool

References

Problem Types

  • SQL Injection CWE
  • Injection CWE