IM
IronMonkey Threat Research

CVE-2025-27631 MEDIUM

Published: 2025-03-25 | Last Modified: 2026-04-15 | Status: Deferred

Description

The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.

Additional Descriptions (1)

La aplicación web TRMTracker es vulnerable a ataques de inyección LDAP que potencialmente permiten a un atacante inyectar código en una consulta y ejecutar comandos remotos que pueden leer y actualizar datos en el sitio web.

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 2.5

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-90
Notification
Message here