


Perceptive Security
SOC/SIEM Consultancy

Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 23:04:16
Source:
nvd.nist.gov
Web Technologies, Database & Storage
CVE-2018-25429 is a SQL injection vulnerability in Paroiciel version 11.20 that allows authenticated attackers to execute arbitrary SQL queries through the zProIdPro parameter in zpro.php. Attackers can exploit this vulnerability by sending crafted GET requests with malicious SQL payloads to extract sensitive database information including usernames, database names, and version details. The vulnerability requires authentication but provides significant access to sensitive data once exploited.
Technical details
Mitigation steps:
Affected products:
Paroiciel
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25429
https://datapacket.dl.sourceforge.net/project/paroiciel/version%2011/par6lus_11_20160225.exe
https://www.exploit-db.com/exploits/45810
https://www.paroiciel.com/
https://www.vulncheck.com/advisories/paroiciel-sql-injection-via-zproidpro-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
