ZeroHour

CVE-2025-67102

PoC
CVSS 3.1
7.6 high
EPSS
<1%p13
Published
()
Modified
Description

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

Vendors
jorani
Products
jorani
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.