GHSA-w832-w3p8-cw29 · Severity: high · Ecosystem: composer — z-push/z-push-dev SQL Injection Vulnerability
Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php define('IMAP_DEFAULTFROM', ''); or php define('IMAP_DEFAULTFROM', 'ldap');
Conclusion & alert: CVE-2025-8264 is rated Moderate Risk (53/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.39%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-25 | 0.07% | 0.39% | +0.32% |
| 2 | 2025-12-25 | 0.15% | 0.07% | -0.08% |
| 3 | 2025-08-30 | — | 0.15% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.9 | 4.0 | HIGH |
|
— | — | [email protected] |
| 9.0 | 3.1 | CRITICAL |
|
2.2 | 6.0 | [email protected] |
GHSA-w832-w3p8-cw29 · Severity: high · Ecosystem: composer — z-push/z-push-dev SQL Injection Vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2025-8264 medium priority: Ubuntu including 1 source packages (z-push), 7 status rows across 7 suites (bionic, focal, jammy, noble, plucky, questing, upstream): needs-triage 4, DNE 3. | https://ubuntu.com/security/CVE-2025-8264 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||