Executive brief
ZIRA Group WBRM is a business software solution used for wholesale billing and revenue management. A security flaw in version 7.0 allows an authorized user with low-level access to manipulate database queries. This could lead to the theft of sensitive customer data, exposure of login credentials, or unauthorized modification of business records.
Technical details
A SQL injection vulnerability exists in the `/pcback/referenceLookupByTableAndColumnName` endpoint of ZIRA Group WBRM 7.0. The root cause is the improper neutralization of the `tableName` and `columnName` parameters, which are directly concatenated into SQL queries without sanitization or parameterization. An authenticated attacker with low privileges can exploit this via crafted GET requests to perform error-based or UNION-based SQL injection. Successful exploitation allows for the extraction of sensitive database information, including user hashes and system versions. As of the advisory date, no official patch has been confirmed by the vendor.
Affected products
- ZIRA Group WBRM 7.0
Timeline
- 2025-07-28: other: Vulnerability discovered during penetration testing
- 2025-07-30: other: Reported to vendor
- 2025-09-25: disclosed: CVE assigned
- 2025-11-24: advisory: NVD publication date