Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-28009 — SQL Injection in Dietiqa App v1.0.20 (CVE-2025-28009) – Unauthenticated remote data access via vulnerable parameter. | Kitploit
Tools/GitHubGitHub/0xs4h4/cve-2025-28009
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationDatabase Security
GitHub0xs4h4/cve-2025-28009

CVE-2025-28009

SQL Injection in Dietiqa App v1.0.20 (CVE-2025-28009) – Unauthenticated remote data access via vulnerable parameter.

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-28009 - SQL Injection in Dietiqa App v1.0.20

Discovered by: Saharuddin Azman
Vendor: Appventure Sdn Bhd
Product: Dietiqa App
Version Affected: v1.0.20
CVE ID: CVE-2025-28009
Vulnerability Type: SQL Injection

📝 Description

A SQL Injection vulnerability exists in the u parameter of the progress-body-weight.php endpoint in Dietiqa App v1.0.20. An attacker can manipulate this parameter to inject arbitrary SQL queries into the backend database. This flaw can be exploited remotely without authentication, posing a serious risk to user data confidentiality and application integrity.

🧪 Technical Summary

  • Vulnerable endpoint: progress-body-weight.php
  • Vulnerable parameter: u
  • Issue: Unsanitized input allows SQL query injection
  • Risk level: High – attackers may access or modify sensitive user data
  • Detailed proof of concept (PoC) has been withheld for ethical and security considerations.

    ✅ Vendor Status

    The vendor, Appventure Sdn Bhd, has acknowledged the vulnerability. A fix is expected in a future release. As of now, version 1.0.20 remains vulnerable.

    🔗 References

    • CVE Record
    • Vendor Website
    • Appventure Sdn Bhd

    ⚠️ Disclosure Ethics

    This issue was disclosed responsibly. The vendor was notified and given time to respond. This repository omits weaponized details and PoC in alignment with responsible disclosure best practices.

    📄 Disclaimer

    This repository is intended for educational and research purposes only.
    Do not attempt to exploit vulnerabilities on systems you do not own or have permission to test.
    The author is not responsible for any misuse of this information.

    Download Tool