CVE-2025-8264
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php define('IMAP_DEFAULTFROM', ''); or php define('IMAP_DEFAULTFROM', 'ldap');
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:P
- EPSS probability
- 0.39%
- CWE
- CWE-89
- Published
- 2025-07-29
- Last modified
- 2026-08-13
Affected products
- n/a z-push/z-push-dev
Weakness type
Related vulnerabilities
- CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr
- CVE-2026-61667 — DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
- CVE-2026-18658 — IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
- CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search
- CVE-2026-77051 — Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search