CVE-2025-8220 | Engeman Web up to 12.0.0.2 Password Recovery Page /Login/RecoveryPass LanguageCombobox sql injection (EUVD-2025-22808)
A vulnerability was found in Engeman Web up to 12.0.0.2. It has been rated as critical. The affected element is an unknown function of the file /Login/RecoveryPass of the component Password Recovery Page. The manipulation of the argument LanguageCombobox as part of Cookie leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-8220. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
The vendor was contacted early about this disclosure but did not respond in any way.