← Back to browse · API

CVE-2025-25181

Severity
MEDIUM
CVSS
5.8
EPSS
0.50863
Risk score
66.0
CISA KEV
Yes
PoC
No
Published
2025-02-03
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-4072, GHSA-6G37-4665-5V4W
Products
Advantive:VeraCore, Advantive:VeraCore 0 ≤2025.1.0
Sources
euvd EUVD-2025-4072
cisa.gov CVE-2025-25181

Description

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

References