What happened
A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · soltanali0/CVE-2025-1094-ExploitWebSocket and SQL Injection Exploit Script★ 41soltanali02025-02-27CandidatePoC-in-GitHub · ishwardeepp/CVE-2025-1094-PoC-Postgre-SQLi★ 6ishwardeepp2025-03-14CandidatePoC-in-GitHub · aninfosec/CVE-2025-1094It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject malicious SQL that the backend executes.★ 1aninfosec2025-06-18CandidatePoC-in-GitHub · PinkArmor/CVE-2025-1094-Lab-Setup★ 0PinkArmor2025-10-19CandidatePoC-in-GitHub · TranDongA3/POC-CVE-2025-1094★ 0TranDongA32026-05-10CandidatePoC-in-GitHub · skraft9/CVE-2024-12356Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)★ 1skraft92026-09-04CandidateSource timeline
Discovered through PoC-in-GitHubView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.