CVE-2025-9943Critical· 9.1▾ MidnightAn SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attac…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database, if the database connection is configured to use the ODBC plugin. The vulnerability arises from insufficient escaping of single quotes in the class SQLString (file odbc-store.cpp, lines 253-271).
This issue affects Shibboleth Service Provider through 3.5.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10601High· 7.3A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10602Medium· 6.3A vulnerability was found in SourceCodester Online Exam Form Submission 1.0
CVE-2025-10598High· 7.3A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0
CVE-2025-10599High· 7.3A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0
CVE-2025-10595Medium· 6.3A vulnerability has been found in SourceCodester Online Student File Management System 1.0
CVE-2025-10596High· 7.3A vulnerability was found in SourceCodester Online Exam Form Submission 1.0