CyberRota Analysis
AI-GeneratedThe vulnerability arises from unsanitized user input in report filtering parameters, which allows for direct concatenation into SQL queries, leading to blind SQL injection. This can result in unauthorized access to sensitive database information. Organizations utilizing affected products should prioritize remediation to protect against potential data breaches and exploitation.
CVE
CVE-2026-64880
Severity
HIGH
CVSS
7.1
EPSS
0.18%
Original NVD Description
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)