Nemon Products SQL Injection Vulnerability Allowing Unauthenticated Access to Two-Factor Authentication

Vulnerability

A SQL injection vulnerability has been identified in Nemon Trade Energy and Nemon Trade Energy CRM, both in version 2.95.55. The issue arises in the 'two_steps_auth_code' parameter, which is processed by the 'twoStepsAuthVerification' function within the '/user-login' endpoint. This vulnerability allows unauthenticated attackers to access the two-factor authentication (2FA) functionality and execute arbitrary SQL queries on the backend database. Exploitation of this vulnerability could lead to database enumeration, unauthorized creation of privileged users, modification or deletion of critical information, and denial-of-service conditions.

Impact

Exploitation of this vulnerability could result in arbitrary SQL execution on the backend database, potentially leading to unauthorized database access, creation of privileged users, manipulation or deletion of important data, and causing denial-of-service conditions.

Added: Jun 9, 2026, 10:32 AM
Updated: Jun 9, 2026, 10:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.