SOUND4 Impact, First, Pulse, and Eco SQL Injection Vulnerability in Authentication Mechanism

Vulnerability

A SQL injection vulnerability has been identified in SOUND4 IMPACT, FIRST, PULSE, and ECO version 2.x. The issue resides in the 'index.php' authentication process, where the 'password' POST parameter is not properly sanitized. This flaw allows attackers to inject malicious SQL code, manipulate login credentials, and bypass authentication, potentially leading to unauthorized access.

Impact

Exploitation of this vulnerability allows for authentication bypass, unauthorized system access, and manipulation of login credentials.

Reproduction

To reproduce this vulnerability, send a POST request to 'index.php' with a crafted 'password' parameter that includes SQL injection payloads. The injection can manipulate SQL queries to bypass authentication.

Added: Dec 22, 2025, 10:24 PM
Updated: Dec 22, 2025, 10:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.