CVE-2025-8264
Last modified
CVE-2025-8264 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php define('IMAP_DEFAULTFROM', ''); or php define('IMAP_DEFAULTFROM', 'ldap');
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-8264?
How severe is CVE-2025-8264?
How do I fix CVE-2025-8264?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8258A vulnerability, which was classified as problematic, has be…5.3
- CVE-2025-8259A vulnerability was identified in Vaelsys VaelsysV4 up to 5.…9.8
- CVE-2025-8260A security flaw has been discovered in Vaelsys VaelsysV4 up …7.5
- CVE-2025-8261A weakness has been identified in Vaelsys VaelsysV4 4.1.0. T…9.8
- CVE-2025-8262A vulnerability was found in yarnpkg Yarn up to 1.22.22. It …7.5
- CVE-2025-8263Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-8265A vulnerability classified as critical has been found in 299…4.7
- CVE-2025-8266A vulnerability has been found in yanyutao0402 ChanCMS up to…6.3
- CVE-2025-8267Versions of the package ssrfcheck before 1.2.0 are vulnerabl…5.3
- CVE-2025-8268The AI Engine plugin for WordPress is vulnerable to unauthor…6.5
- CVE-2025-8269A vulnerability was found in code-projects Exam Form Submiss…9.8
- CVE-2025-8270A vulnerability was found in code-projects Exam Form Submiss…9.8
Are you affected by CVE-2025-8264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
