CVE-2025-25181: Advantive VeraCore SQL Injection Vulnerability
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
Other sources
Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25181?
CVE-2025-25181 has been assessed as a high severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2025-25181?
To fix CVE-2025-25181, it is recommended to update Advantive VeraCore to a version that is later than 2025.1.0.
What is CVE-2025-25181?
CVE-2025-25181 is a SQL injection vulnerability in the timeoutWarning.asp file of Advantive VeraCore that allows attackers to execute arbitrary SQL commands.
Who is affected by CVE-2025-25181?
CVE-2025-25181 affects users of Advantive VeraCore versions up to and including 2025.1.0.
How can I determine if I am vulnerable to CVE-2025-25181?
You can determine if you are vulnerable to CVE-2025-25181 by checking your current version of Advantive VeraCore and ensuring it is beyond 2025.1.0.