
SQL Injection in Dietiqa App v1.0.20 (CVE-2025-28009) – Unauthenticated remote data access via vulnerable parameter.
Discovered by: Saharuddin Azman
Vendor: Appventure Sdn Bhd
Product: Dietiqa App
Version Affected: v1.0.20
CVE ID: CVE-2025-28009
Vulnerability Type: SQL Injection
A SQL Injection vulnerability exists in the u parameter of the progress-body-weight.php endpoint in Dietiqa App v1.0.20. An attacker can manipulate this parameter to inject arbitrary SQL queries into the backend database.
This flaw can be exploited remotely without authentication, posing a serious risk to user data confidentiality and application integrity.
progress-body-weight.phpuDetailed proof of concept (PoC) has been withheld for ethical and security considerations.
The vendor, Appventure Sdn Bhd, has acknowledged the vulnerability. A fix is expected in a future release. As of now, version 1.0.20 remains vulnerable.
This issue was disclosed responsibly. The vendor was notified and given time to respond. This repository omits weaponized details and PoC in alignment with responsible disclosure best practices.
This repository is intended for educational and research purposes only.
Do not attempt to exploit vulnerabilities on systems you do not own or have permission to test.
The author is not responsible for any misuse of this information.