Buroweb Platform SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Buroweb platform, specifically in version 2505.0.12 within the 'tablon' component. The issue arises in several parameters of the endpoint '/sta/CarpetaPublic/doEvent?APP_CODE=STA&PAGE_CODE=TABLON', where user input is not properly sanitized. This vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access to confidential database information.

Impact

Exploitation of this vulnerability could allow attackers to execute SQL queries on the database, with the potential to access sensitive information.

Remediation

Users are advised to update to Buroweb version 2505.0.13 or, if unavailable, to the latest stable version.

Added: Feb 3, 2026, 12:21 PM
Updated: Feb 3, 2026, 5:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.4
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.