← Vulnerability feed

Vulnerability record · CVE-2020-25132 · published 25 September 2020

CVE-2020-25132: Observium sql injection vulnerability

Observium · Observium

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. Sending the improper variable type Array allows a bypass of core SQL Injection sanitization. Users are able to inject malicious statements in multiple functions. This vulnerability leads to full authentication bypass: any unauthorized user with access to the application is able to exploit this vulnerability. This can occur via the Cookie header to the default URI, within includes/authenticate.inc.php.

9.8 CVSS 3.1 Critical EPSS 1.6% · top 25.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. Sending the improper variable type Array allows a bypass of core SQL Injection sanitization. Users are able to inject malicious statements in multiple functions. This vulnerability leads to full authentication bypass: any unauthorized user with access to the application is able to exploit this vulnerability. This can occur via the Cookie header to the default URI, within includes/authenticate.inc.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-25132 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-25147Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.4%8.8CVE-2020-25143Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.2%8.8CVE-2020-25144Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25145Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25149Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25136Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.0%8.8CVE-2020-25134Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.4%8.8CVE-2020-25133Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2020-25132), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.