CVE-2026-25606 PUBLISHED

SQL Injection in STER

Assigner: CERT-PL
Reserved: 03.02.2026 Published: 22.05.2026 Updated: 22.05.2026

A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access

This issue was fixed in version 9.5.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy
Product STER
Versions Default: unaffected
  • affected from 0 to 9.5 (excl.)

Credits

  • Michelin CERT finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection