- Description
- A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full administrative access to the application, including the ability to manipulate the public-facing website content (HTML/DOM manipulation).
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
- CNA Tags
- exclusively-hosted-service
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@mitre.org
- CWE-89
- Hype score
- Not currently trending
[CVE-2025-10878: CRITICAL] SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 pre-2026 allows attackers to bypass login, gain admin access, and manipulate website content. Immediate update recomme...#cve,CVE-2025-10878,#cybersecurity https://t.co/6GsEEhS1Br
@CveFindCom
3 Feb 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2025-10878 - Critical A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, ... https://t.co/aJsogAMezC https://t.co/yMsMwfr3rm
@TheHackerWire
3 Feb 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10878 A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerab… https://t.co/r76VCAyDui
@CVEnew
3 Feb 2026
299 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-10878 PoC for CVE-2025-10878 https://t.co/vivlGVKB2f
@VulmonFeeds
29 Jan 2026
72 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes