Article

    Cyber News / Article / Vulnerabilities in STER software

    Vulnerabilities in STER software
    CE
    CERT Polska-2026-05-22

    Vulnerabilities in STER software

    CERT Polska has received a report about vulnerabilities in STER software and participated in coordination of their disclosure.

    The vulnerabilityCVE-2026-25606: A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multiple Search Filters allows for SQL Injection attacks. It allows an authenticated attacker to view sensitive data such as data belonging to other users, or any other data that the application itself is able to access

    The vulnerabilityCVE-2026-25607: Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.

    The vulnerabilityCVE-2026-25608: STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens.

    These issues were fixed in version 9.5.

    We thank Michelin CERT for the responsible vulnerability report.

    Original source