CVE-2025-8126 | deerwms deer-wms-2 up to 3.3 /system/user/export params[dataScope] sql injection (ICLQUE / EUVD-2025-22562)
A vulnerability was found in deerwms deer-wms-2 up to 3.3 and classified as critical. The affected element is an unknown function of the file /system/user/export. Such manipulation of the argument params[dataScope] leads to sql injection.
This vulnerability is referenced as CVE-2025-8126. It is possible to launch the attack remotely. Furthermore, an exploit is available.