PT-2025-27359 · Esapi+3 · Esapi+3
Longlong Gong
+1
·
Published
2025-06-29
·
Updated
2026-04-16
·
CVE-2025-5878
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
ESAPI esapi-java-legacy versions prior to 2.7.0.0
Description:
A vulnerability was found in the interface
Encoder.encodeForSQL of the SQL Injection Defense, leading to an improper neutralization of special elements. The attack may be initiated remotely. This issue affects the SQL Injection Defense, allowing for potential exploitation. The project handled the issue professionally after being contacted.Recommendations:
For versions prior to 2.7.0.0, upgrade to version 2.7.0.0 to address this issue. As a temporary workaround, consider disabling the
Encoder.encodeForSQL interface until the update is applied.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Esapi
Linuxmint
Ubuntu