CVE-2025-58448: rAthena has SQL Injection in PartyBooking component via `WorldName` parameter.
Published Sep 9, 2025
·Updated
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking component via WorldName parameter. Commit 0d89ae0 fixes the issue.
Affected Software
2 affected components
rAthena rAthena<0d89ae0
rAthena rAthena<2025-09-06
Remediation
Event History
Sep 9, 2025
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58448?
CVE-2025-58448 is classified as a critical vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2025-58448?
To fix CVE-2025-58448, update rAthena to a version that is 0d89ae0 or later.
3
What software is affected by CVE-2025-58448?
CVE-2025-58448 affects all versions of rAthena prior to commit 0d89ae0.
4
What type of vulnerability is CVE-2025-58448?
CVE-2025-58448 is a SQL Injection vulnerability found in the PartyBooking component of rAthena.
5
What is the impact of exploiting CVE-2025-58448?
Exploiting CVE-2025-58448 could allow an attacker to execute arbitrary SQL commands in the database.