A Boolean-based SQL injection vulnerability was...
Critical severity
Unreviewed
Published
Aug 4, 2025
to the GitHub Advisory Database
•
Updated Aug 5, 2025
Description
Published by the National Vulnerability Database
Aug 4, 2025
Published to the GitHub Advisory Database
Aug 4, 2025
Last updated
Aug 5, 2025
A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.
References