SQL Injection Vulnerabilities Discovered in Kolay and DATABASE Software

SQL Injection Vulnerabilities Discovered in Kolay and DATABASE Software

First seen 20 Feb 2026, 23:17 UTC Feedly 39.1

Article Content

Browse articles
ThreatCluster

Two SQL injection vulnerabilities have been identified in software from Kolay Software Inc. and DATABASE Software Training Consulting Ltd. The vulnerabilities, CVE-2025-10970 and CVE-2025-9953, allow unauthenticated attackers to execute SQL injection attacks, potentially bypassing authorization controls. Both vendors were contacted but did not respond to the disclosures.

Timeline

2026-02-19
CVE-2025-9953 published
2026-02-19
CVE-2026-25755 published
2026-02-20
CVE-2025-10970 published