Paroiciel SQL Injection Vulnerability in trec.php Endpoint

Vulnerability

A SQL injection vulnerability has been identified in Paroiciel version 11.20. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious payloads through the tRecIdListe parameter. Exploitation involves sending GET requests to the trec.php endpoint with crafted SQL injections that can manipulate the database and extract information such as table and column names.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the application's database.

Reproduction

To reproduce this vulnerability, send a GET request to the trec.php endpoint with the tRecIdListe parameter. Inject a SQL payload that exploits the application's SQL query handling. The injected SQL can be crafted to, for example, union select database information such as table and column names.

Added: Jun 1, 2026, 11:08 PM
Updated: Jun 1, 2026, 11:08 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.