


Perceptive Security
SOC/SIEM Consultancy

Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 23:04:16
Source:
nvd.nist.gov
Web Technologies, Database & Storage
Paroiciel version 11.20 contains an SQL injection vulnerability (CVE-2018-25430) that affects authenticated users. The vulnerability exists in the eGeqIdEquipe parameter of the egeq.php endpoint. Attackers can exploit this flaw by sending crafted GET requests with malicious SQL payloads. Successful exploitation allows arbitrary SQL query execution against the application database. The vulnerability enables extraction of sensitive database information including version details and other stored data. This represents a significant data confidentiality risk for affected Paroiciel installations.
Technical details
Mitigation steps:
Affected products:
Paroiciel
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25430
https://datapacket.dl.sourceforge.net/project/paroiciel/version%2011/par6lus_11_20160225.exe
https://www.exploit-db.com/exploits/45810
https://www.paroiciel.com/
https://www.vulncheck.com/advisories/paroiciel-sql-injection-via-egeqidequipe-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
