CVE-2025-52924

In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jul 2025, 16:15

Type Values Removed Values Added
CWE CWE-89

19 Jul 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-19 03:15

Updated : 2025-07-23 16:15


NVD link : CVE-2025-52924

Mitre link : CVE-2025-52924


JSON object : View

Products Affected

No product.

CWE

No CWE.