CVE-2025-26086

An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:rsiqueue:management_system:3.0:*:*:*:*:*:*:*

History

12 Jun 2025, 16:20

Type Values Removed Values Added
CPE cpe:2.3:a:rsiqueue:management_system:3.0:*:*:*:*:*:*:*
First Time Rsiqueue
Rsiqueue management System
References () http://seclists.org/fulldisclosure/2025/May/21 - () http://seclists.org/fulldisclosure/2025/May/21 - Mailing List
References () https://seclists.org/fulldisclosure/2025/May/21 - () https://seclists.org/fulldisclosure/2025/May/21 - Mailing List

20 May 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-20 15:16

Updated : 2025-06-12 16:20


NVD link : CVE-2025-26086

Mitre link : CVE-2025-26086


JSON object : View

Products Affected

rsiqueue

  • management_system
CWE

No CWE.