CVE-2025-6230

A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lenovo:commercial_vantage:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-17 20:15

Updated : 2026-06-17 10:01


NVD link : CVE-2025-6230

Mitre link : CVE-2025-6230

CVE.ORG link : CVE-2025-6230


JSON object : View

Products Affected

lenovo

  • vantage
  • commercial_vantage
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')