PatchSiren cyber security CVE debrief
CVE-2025-41029 Zeon Global Tech CVE debrief
A critical SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech allows unauthenticated remote attackers to execute arbitrary SQL commands via the 'phonenumber' parameter in /private/continue-upload.php. The vulnerability permits full database manipulation including retrieval, creation, modification, and deletion of data. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, and high impact across confidentiality, integrity, and availability. The vulnerability was disclosed by INCIBE-CERT (Spanish National Cybersecurity Institute) and carries a 'Deferred' status in NVD, suggesting the vendor has not yet provided a patch or response.
- Vendor
- Zeon Global Tech
- Product
- Zeon Academy Pro
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-05-19
Who should care
Organizations running Zeon Academy Pro; security teams managing educational or training platform infrastructure; database administrators responsible for application security; incident response teams monitoring for data breach indicators
Technical summary
The vulnerability exists in the /private/continue-upload.php endpoint where user-supplied input via the 'phonenumber' POST parameter is concatenated directly into SQL queries without proper sanitization or parameterization. This classic SQL injection flaw (CWE-89) enables attackers to manipulate query logic, potentially extracting sensitive data, modifying records, or executing administrative database operations. The endpoint's location in a 'private' directory suggests it may be intended for authenticated use, but the vulnerability description indicates no authentication is required for exploitation.
Defensive priority
critical
Recommended defensive actions
- Apply input validation and parameterized queries to the 'phonenumber' parameter in /private/continue-upload.php
- Implement prepared statements or stored procedures to eliminate SQL injection vectors
- Restrict database privileges for the application user to least-privilege principles
- Deploy Web Application Firewall (WAF) rules to detect and block SQL injection attempts against the identified endpoint
- Monitor for anomalous POST requests to /private/continue-upload.php containing SQL keywords or special characters
- Contact Zeon Global Tech for official patch availability given NVD 'Deferred' status
- Conduct database audit logs review for unauthorized schema modifications or data exfiltration attempts
Evidence notes
Vulnerability disclosed by INCIBE-CERT with official CVE assignment. NVD status 'Deferred' indicates vendor coordination may be incomplete. No known exploitation in the wild (KEV negative). CVSS 4.0 scoring applied.
Official resources
-
CVE-2025-41029 CVE record
CVE.org
-
CVE-2025-41029 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-04-21