← Back to browse · API

CVE-2025-10878

Severity
CRITICAL
CVSS
10.0
EPSS
0.00602
Risk score
40.21
CISA KEV
No
PoC
No
Published
2026-02-03
Modified
2026-02-04
First seen
2026-08-07
Aliases
EUVD-2025-206676, GHSA-66JJ-X34Q-V9C3
Products
Insaat:Fikir Odalari AdminPando 1.0.1
Sources
euvd EUVD-2025-206676

Description

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full administrative access to the application, including the ability to manipulate the public-facing website content (HTML/DOM manipulation).

References