PT-2025-18680 · Adodb+3 · Adodb+3

Xaliom

·

Published

2025-05-01

·

Updated

2025-09-03

·

CVE-2025-46337

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ADOdb versions prior to 5.22.9
Description The issue is related to the improper escaping of a query parameter, which may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and invokes the pg insert id() function with user-supplied data.
Recommendations For versions prior to 5.22.9, update to version 5.22.9 to resolve the issue. As a temporary workaround, consider restricting the use of the pg insert id() function with user-supplied data until the patch is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06864
CVE-2025-46337
DLA-4177-1
GHSA-8X27-JWJR-8545
MGASA-2025-0179
USN-7530-1

Affected Products

Adodb
Debian
Red Os
Ubuntu