CVE-2025-3164 | Tencent Music Entertainment SuperSonic up to 0.9.8 H2 Database Connection testConnect code injection (Issue 2193)
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection.
This vulnerability is handled as CVE-2025-3164. The attack may be launched remotely. Furthermore, there is an exploit available.