PT-2025-18680 · Adodb+3 · Adodb+3
Xaliom
·
Published
2025-05-01
·
Updated
2025-09-03
·
CVE-2025-46337
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
ADOdb versions prior to 5.22.9
Description
The issue is related to the improper escaping of a query parameter, which may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and invokes the
pg insert id() function with user-supplied data.Recommendations
For versions prior to 5.22.9, update to version 5.22.9 to resolve the issue.
As a temporary workaround, consider restricting the use of the
pg insert id() function with user-supplied data until the patch is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adodb
Debian
Red Os
Ubuntu