← Back

CVE-2025-59379

nvd nist
Published: Jan 6, 2026Modified: Jan 29, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and admins) and use them to authenticate to the application.

Affected (1)

1 product
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.5.7
Running on/withPlatform Versions
Dwyeromega
Isensix Advanced Remote Monitoring System
All versions

References (3)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Product

Timeline

No history available yet.