HIGH
CVE-2025-25181
CVSS
7.5
KEV
Description
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
Summary dbcve.org
SQL injection vulnerability in the PmSess1 parameter of timeoutWarning.asp in Advantive VeraCore allows remote attackers to inject arbitrary SQL commands. The flaw stems from unsanitized user input being directly incorporated into SQL queries.
Mitigation
Apply parameterized queries or prepared statements for the PmSess1 parameter in timeoutWarning.asp, validate all user inputs, and implement the vendor patch for version 2025.1.0 when available.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
57.3%
Probability of exploitation in next 30 days
99.1th percentile
References
https://advantive.my.site.com/support/s/knowledge
Product, Release Notes
https://intezer.com/blog/research/xe-group-exploiting-zero-days/
Exploit, Technical Description, Third Party Advisory
https://www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/
Exploit, Technical Description, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25181
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.