Realce Tecnologia Queue Ticket Kiosk SQL Injection Vulnerability in Admin Login Page
Vulnerability
A critical SQL injection vulnerability has been identified in Realce Tecnologia Queue Ticket Kiosk versions prior to 20250517. The issue arises in the Admin Login Page component, specifically within the file /adm/index.php. The vulnerability allows remote attackers to manipulate the 'Usuário' argument, leading to unauthorized database access or manipulation.
Impact
Exploitation of this vulnerability allows for SQL injection, enabling attackers to interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
