AI description
CVE-2025-46337 is an SQL injection vulnerability found in ADOdb, a PHP database class library. Specifically, it affects the `pg_insert_id()` function when ADOdb connects to a PostgreSQL database. The vulnerability stems from improper escaping of a query parameter, which could allow an attacker to execute arbitrary SQL statements. This vulnerability occurs when user-supplied data is passed to the `pg_insert_id()` method's `$fieldname` parameter without proper sanitization. This could enable attackers to manipulate the SQL query, potentially leading to data theft, deletion, or even remote code execution. The issue was addressed in ADOdb version 5.22.9.
- Description
- ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-89
- Hype score
- Not currently trending
⚠️ Critical SQLi flaw in ADOdb (CVE-2025-46337) impacts #Ubuntu 25.04/24.10! Attackers can execute arbitrary SQLRead more: 👇https://t.co/birpXUPcOm https://t.co/3SDrDvgloK
@Cezar_H_Linux
2 Jun 2025
35 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
URGENT: Fedora 41 security update patches critical SQL injection flaw (CVE-2025-46337) in PHP-ADOdb PostgreSQL driver. Enterprise PHP apps at risk! Update command: su -c 'dnf upgrade --advisory FEDORA-2025-a32ccde763' Read more: 👉 https://t.co/xY3DnpLGx0 #Fedora #Security ht
@Cezar_H_Linux
11 May 2025
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
世界中で280万以上のインストール実績を持つPHPのデータベース抽象化ライブラリ「ADOdb」に重大な脆弱性(CVE-2025-46337)が報告された。 PostgreSQLドライバのpg_insert_id()メソッドにおける不適切なクエリパラメー
@yousukezan
5 May 2025
3025 Impressions
7 Retweets
25 Likes
11 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerability Alert: Critical SQL Injection Vulnerability in ADOdb PHP Library 📅 Timeline: Disclosure: 2025-05-01, Patch: 2025-05-01 🆔 cveId: CVE-2025-46337 📊 baseScore: 10.0 📏 cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L cvssSeverity: C
@syedaquib77
5 May 2025
64 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Critical SQL Injection Vulnerability Found in ADOdb PHP Library – CVE-2025-46337 (CVSS 10.0) https://t.co/1UQAVPV90N
@Dinosn
5 May 2025
971 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-3776 2 - CVE-2024-26809 3 - CVE-2025-46337 4 - CVE-2025-26529 5 - CVE-2025-32433 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
4 May 2025
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-46337 ⚠️🔴 CRITICAL (10) 🏢 ADOdb - ADOdb 🏗️ < 5.22.9 🔗 https://t.co/50YmRX4hcn 🔗 https://t.co/URfDiMYiYk 🔗 https://t.co/FXJfljkCuu #CyberCron #VulnAlert #InfoSec https://t.co/4WJdQxuuwL
@cybercronai
3 May 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-46337 ⚠️🔴 CRITICAL (10) 🏢 ADOdb - ADOdb 🏗️ < 5.22.9 🔗 https://t.co/50YmRX4hcn 🔗 https://t.co/URfDiMYiYk 🔗 https://t.co/FXJfljkCuu #CyberCron #VulnAlert #InfoSec https://t.co/KP0XCVxmlI
@cybercronai
2 May 2025
1870 Impressions
3 Retweets
4 Likes
0 Bookmarks
0 Replies
1 Quote
⚠️Múltiples vulnerabilidades del kernel de Linux Red Hat ❗CVE-2025-46337 ❗CVE-2025-21927 ❗CVE-2025-22869 ❗CVE-2025-30204 ❗CVE-2025-24209 ➡️Más info: https://t.co/T4ViIi50N9 https://t.co/rpOVorctqA
@CERTpy
2 May 2025
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-46337 ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query … https://t.co/HMN707zXUO
@CVEnew
1 May 2025
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-46337: CRITICAL] Vulnerable ADOdb versions allowed SQL injection via pg_insert_id(). Make sure to update to version 5.22.9 to stay protected against cyber attacks. #cybersecurity#cve,CVE-2025-46337,#cybersecurity https://t.co/XieGJGeJDk https://t.co/HodoHUFcgr
@CveFindCom
1 May 2025
21 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes