Posted by Shaikh Shahnawaz on May 16
[+] Credits: Shahnawaz Shaikh, Security Researcher at Cybergate Defense LLC
[+] twitter.com/_striv3r_
[Vendor of Product]
RSI Queue (https://www.rsiqueue.com/)
[Vulnerability Type]
Blind SQL Injection
[Affected Component]
The vulnerable component is the TaskID parameter in the get request.
[CVE Reference]
CVE-2025-26086
[Security Issue]
An unauthenticated blind SQL injection vulnerability exists in RSI Queue
Management System v3.0 within the…
– Read More – Full Disclosure