CVE-2025-34059

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Jul 2025, 15:14

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección SQL en Dahua Smart Cloud Gateway Registration Management Platform a través del parámetro de nombre de usuario en el endpoint /index.php/User/doLogin. La aplicación no depura correctamente la entrada del usuario, lo que permite a atacantes no autenticados inyectar sentencias SQL arbitrarias y potencialmente divulgar información confidencial.

01 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-01 15:15

Updated : 2025-07-03 15:14


NVD link : CVE-2025-34059

Mitre link : CVE-2025-34059

CVE.ORG link : CVE-2025-34059


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor