CVE-2025-67811

A

rea9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient input validation allows remote attackers to inject arbitrary SQL commands, resulting in unauthorized database access and potential compromise of sensitive data. Fixed in v.1.47.4 and beyond.

References
Link Resource
https://area9.com Broken Link
https://security.area9lyceum.com/cve-2025-67811/ Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:area9lyceum:rhapsode:1.47.3:*:*:*:*:*:*:*

History

10 Feb 2026, 19:45

Type Values Removed Values Added
CPE cpe:2.3:a:area9lyceum:rhapsode_learner:1.47.3:*:*:*:*:*:*:* cpe:2.3:a:area9lyceum:rhapsode:1.47.3:*:*:*:*:*:*:*
First Time Area9lyceum rhapsode

23 Jan 2026, 15:58

Type Values Removed Values Added
CPE cpe:2.3:a:area9lyceum:rhapsode_learner:1.47.3:*:*:*:*:*:*:*
References () https://area9.com - () https://area9.com - Broken Link
References () https://security.area9lyceum.com/cve-2025-67811/ - () https://security.area9lyceum.com/cve-2025-67811/ - Vendor Advisory
First Time Area9lyceum
Area9lyceum rhapsode Learner

09 Jan 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 20:15

Updated : 2026-02-10 19:45


NVD link : CVE-2025-67811

Mitre link : CVE-2025-67811

CVE.ORG link : CVE-2025-67811


JSON object : View

Products Affected
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')