CVE-2025-22992

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-22992
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22992.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-22992
Published
2025-02-06T19:15:19Z
Modified
2025-07-31T16:56:55.446328Z
Summary
[none]
Details

A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions.

References

Affected packages

Git / github.com/emoncms/emoncms

Affected ranges

Type
GIT
Repo
https://github.com/emoncms/emoncms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

10.*

10.0.0
10.0.2
10.1.0
10.1.1
10.1.10
10.1.11
10.1.2
10.1.3
10.1.4
10.1.5
10.1.6
10.1.7
10.1.8
10.1.9
10.2.0
10.2.1
10.2.2
10.2.3
10.2.4
10.2.5
10.2.7
10.4
10.5.5
10.5.6
10.6.5
10.6.6
10.6.7
10.6.8
10.6.9
10.7.0
10.7.1
10.7.2
10.7.3
10.7.4
10.7.7
10.8.1
10.8.5

11.*

11.0.5
11.0.8
11.0.9
11.2.10
11.2.11
11.2.12
11.2.13
11.2.3
11.2.7
11.2.8
11.2.9
11.3.0
11.3.20
11.3.22
11.4.10
11.4.11
11.4.2
11.4.3
11.4.4
11.4.5
11.4.7
11.4.9
11.5.2
11.5.3
11.5.5
11.5.6
11.6.1
11.6.2
11.6.4
11.6.5
11.6.6
11.6.7
11.6.8
11.6.9

8.*

8.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.0.7
8.0.8
8.0.9
8.1.0
8.1.1
8.1.2
8.2
8.2.1
8.2.2
8.2.3
8.2.4
8.2.5
8.2.6
8.2.7
8.2.8
8.3.0
8.3.1
8.5.2

9.*

9.3.0
9.4
9.5.0
9.5.1
9.6.0
9.7.0
9.7.1
9.7.2
9.7.3
9.7.6
9.7.7
9.7.9
9.8.1
9.8.10
9.8.11
9.8.13
9.8.15
9.8.15.stable
9.8.16
9.8.18
9.8.24
9.8.25
9.8.27
9.8.28
9.8.29
9.8.3
9.8.30
9.8.31
9.8.4
9.8.6
9.8.7
9.8.8
9.9.0
9.9.3
9.9.4
9.9.5
9.9.6
9.9.7
9.9.8
9.9.9

V9.*

V9.9.2

debian/8.*

debian/8.0-1

Other

emonSD-22Dec2015

v5.*

v5.0

v6.*

v6.0
v6.9

v7.*

v7.0

v8.*

v8.3.2
v8.3.3
v8.3.4
v8.3.5
v8.3.6
v8.4.0

v9.*

v9.3
v9.4
v9.5
v9.5.1
v9.6
v9.7
v9.7.1
v9.9.0
v9.9.1