Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-55472

SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerability arises due to unsafe handling of user-supplied input in the columns[0][data] parameter, which is directly used in SQL queries without proper validation or parameterization.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.9%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-55472
  • Tirreno » Tirreno » Version: 0.9.5
    cpe:2.3:a:tirreno:tirreno:0.9.5


Contact Us

Shodan ® - All rights reserved