PT-2025-31792 · Sqlite3+3 · Sqlite3+3

·

CVE-2025-54119

·

Published

2025-08-03

·

Updated

2025-10-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ADOdb version 5.22.10
Description Improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when connecting to a sqlite3 database and calling the metaColumns(), metaForeignKeys(), or metaIndexes() methods with a crafted table name. The vulnerability exists in the SQLite3 driver.
Recommendations Only pass controlled data to the $table parameter of the metaColumns(), metaForeignKeys(), and metaIndexes() methods.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10815
CVE-2025-54119
DLA-4340-1
GHSA-VF2R-CXG9-P7RF

Affected Products

Adodb
Debian
Red Os
Sqlite3