CVE-2025-52924
19.07.2025, 03:15
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Awaiting analysis
This vulnerability is currently awaiting analysis.