- Description
- AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries.
- Source
- 4760f414-e1ae-4ff1-bdad-c7a9c3538b79
- NVD status
- Analyzed
- Products
- on-prem_enterprise_server
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- 4760f414-e1ae-4ff1-bdad-c7a9c3538b79
- CWE-20
- Hype score
- Not currently trending
CVE-2025-27378 (CVSS:8.6, HIGH) is Awaiting Analysis. AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f..https://t.co/5O6EHWemWB #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
27 Jan 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27378 - AES SQL injection via inactive config preventing latest SQL parsing logic Check: grep -r "sql.parsing" /path/to/aes/config/ Source: https://t.co/cl4U9v0Ens
@lsof
22 Jan 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27378 SQL Injection in AES Due to Inactive Configuration Bypass https://t.co/ZlznVjJVIQ Vulnerability Notification: https://t.co/xhLrNnfyrO
@VulmonFeeds
22 Jan 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is … https://t.co/tCHvEuNyRf
@CVEnew
22 Jan 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-27378: HIGH] Avoid SQL injection vulnerability in AES by activating latest SQL parsing logic in the configuration to prevent crafted input from being mishandled and exploited by attackers. #cyberse...#cve,CVE-2025-27378,#cybersecurity https://t.co/jTHbO8QJV0 https://t.c
@CveFindCom
22 Jan 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🟠 CVE-2025-27378 - High AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted inpu... https://t.co/Eu9NRnTxP9 https://t.co/CxfEuGf20p
@TheHackerWire
22 Jan 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:altium:on-prem_enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3F31D6A7-989F-4647-AA13-38737112E369",
"versionEndExcluding": "7.0.6",
"versionStartIncluding": "7.0.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]