GHSA-h8h7-vv55-qhxgCriticalCVSS 10.0

Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization...

Published
September 18, 2025
Last Modified
June 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Logo Software Retail Sales Management allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Retail Sales Management: through 20250918. 

NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.

🔗 References (4)