CVE-2025-48141
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment allows SQL Injection....
Affects 0 products across 2 vendors.
Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A SQL Injection vulnerability exists in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment, affecting versions up to 2.0.7. This vulnerability could allow an attacker to manipulate SQL queries, potentially leading to unauthorized data access, modification, or deletion.
BSID: BS-2025-GLOBAL-245325-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-48141?
What is the CVSS score for CVE-2025-48141?
Is CVE-2025-48141 actively exploited?
How do I remediate CVE-2025-48141?
What systems are affected by CVE-2025-48141?
| CVE ID | CVE-2025-48141 |
|---|---|
| BSID | BS-2025-GLOBAL-245325-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L |
| Published | 2025-06-09 |
| Last Modified | 2026-04-23 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment allows SQL Injection.This issue affects Multi CryptoCurrency Payments: from n/a through <= 2.0.7.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from improper neutralization of special elements used in SQL commands. An attacker can inject malicious SQL code through input fields that are not properly sanitized, leading to unauthorized database operations.
Exploitation Likelihood: HIGH
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 082143590bf16a7b365498afb9ba6222c5459c71dbbdcf02608a51077053d966d84f23f6682545d02df8b31214425518d71c52ebf86800a15136c6e47c9d73d9 |
Critical Severity - Know Your Exposure
A CVSS 9.3 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →