CVE-2018-25187: TINA4 Stack
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu endpoint to manipulate database queries.
Affected products
- TINA4 TINA4 Stack: version 1.0.3 only
Published 2026-03-06. Last modified 2026-06-17.