CVE-2025-6918
SQLi in Ncvav's Virtual PBX Software
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.
This issue affects Virtual PBX Software: before 09.07.2025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Ncvav · Virtual PBX SoftwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →