STER SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability exists in the STER application, developed by the Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy. This vulnerability arises from improper handling of user input in multiple search filters, allowing authenticated attackers to execute SQL injection attacks. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, including information belonging to other users or any data the application can access. All versions of STER prior to 9.5 are affected.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to manipulate database queries and potentially access or modify sensitive data.

Remediation

Users can upgrade to STER version 9.5 to address this vulnerability.

Added: May 22, 2026, 10:19 AM
Updated: May 22, 2026, 10:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.