Sceawere
Vulnerability Detail
CVE-2026-105076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Vitepos Lite Blind SQLi
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 4h ago
- Vendor
- Appsbd
- Product
- Vitepos
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through 3.6.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-10-08T13:17:12.763Z",
"pubdate": "2026-10-08T13:17:12.763Z",
"executiveSummary": "A critical security vulnerability, classified under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), has been identified in the Appsbd Vitepos 'vitepos-lite' plugin. This vulnerability affects all versions of Vitepos from network availability (n/a) through 3.6.1.\nThe flaw facilitates Blind SQL Injection, a severe class of vulnerability that allows remote attackers to manipulate backend database queries without direct data exposure in the application's response. By exploiting this vulnerability, an attacker can systematically infer the contents of the database, including sensitive user credentials, configuration settings, and proprietary business data.\nDepending on the configuration and privileges of the database user, successful exploitation could lead to unauthorized data extraction, authentication bypass, or potential administrative takeover of the host system. The risk implication is significant due to the potential for automated harvesting of sensitive information, posing a direct threat to confidentiality and data integrity.",
"technicalDetails": "The root cause of this vulnerability lies in the improper neutralization of user-supplied input before it is concatenated into SQL statements within the 'vitepos-lite' plugin. Specifically, the application fails to utilize prepared statements or parameterized queries when handling certain input parameters, allowing special characters to alter the logic of the SQL command executed by the backend database.\nBecause this is a Blind SQL Injection vulnerability, the application does not return SQL error messages or query results directly on the screen. Instead, attackers must rely on boolean-based or time-based inference techniques to extract data. In a typical attack flow, an unauthorized user sends crafted HTTP requests containing malicious payloads embedded in vulnerable parameters.\nFor a boolean-based blind attack, the payload consists of conditional statements (e.g., 'AND 1=1' versus 'AND 1=2'). If the application behaves differently based on the truth value of the injected condition (such as displaying a different UI element or omitting certain records), the attacker can determine the status of database attributes character by character.\nFor a time-based blind attack, the injected payload contains time-delay functions (e.g., 'sleep()'). The database engine pauses execution if the injected condition is true, resulting in a delayed HTTP response. By measuring the round-trip time of the server's response, the attacker confirms the validity of their logical test.\nThrough iterative querying, an attacker can reconstruct entire database schemas, extract sensitive hashes, or identify session identifiers. While the vulnerability exists within the vitepos-lite plugin code, its operational impact is heavily dictated by the database user's privileges. If the database user has elevated permissions, the impact could extend to reading local files or writing web shells to the server file system, resulting in complete system compromise."
}