CVE-2025-46337

Published May 1, 2025

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-46337 is an SQL injection vulnerability found in ADOdb, a PHP database class library. Specifically, it affects the `pg_insert_id()` function when ADOdb connects to a PostgreSQL database. The vulnerability stems from improper escaping of a query parameter, which could allow an attacker to execute arbitrary SQL statements. This vulnerability occurs when user-supplied data is passed to the `pg_insert_id()` method's `$fieldname` parameter without proper sanitization. This could enable attackers to manipulate the SQL query, potentially leading to data theft, deletion, or even remote code execution. The issue was addressed in ADOdb version 5.22.9.

Description
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-89

Social media

Hype score
Not currently trending
  1. ⚠️ Critical SQLi flaw in ADOdb (CVE-2025-46337) impacts #Ubuntu 25.04/24.10! Attackers can execute arbitrary SQLRead more: 👇https://t.co/birpXUPcOm https://t.co/3SDrDvgloK

    @Cezar_H_Linux

    2 Jun 2025

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. URGENT: Fedora 41 security update patches critical SQL injection flaw (CVE-2025-46337) in PHP-ADOdb PostgreSQL driver. Enterprise PHP apps at risk! Update command: su -c 'dnf upgrade --advisory FEDORA-2025-a32ccde763' Read more: 👉 https://t.co/xY3DnpLGx0 #Fedora #Security ht

    @Cezar_H_Linux

    11 May 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 世界中で280万以上のインストール実績を持つPHPのデータベース抽象化ライブラリ「ADOdb」に重大な脆弱性(CVE-2025-46337)が報告された。 PostgreSQLドライバのpg_insert_id()メソッドにおける不適切なクエリパラメー

    @yousukezan

    5 May 2025

    3025 Impressions

    7 Retweets

    25 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Vulnerability Alert: Critical SQL Injection Vulnerability in ADOdb PHP Library 📅 Timeline: Disclosure: 2025-05-01, Patch: 2025-05-01 🆔 cveId: CVE-2025-46337 📊 baseScore: 10.0 📏 cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L cvssSeverity: C

    @syedaquib77

    5 May 2025

    64 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  5. Critical SQL Injection Vulnerability Found in ADOdb PHP Library – CVE-2025-46337 (CVSS 10.0) https://t.co/1UQAVPV90N

    @Dinosn

    5 May 2025

    971 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. Top 5 Trending CVEs: 1 - CVE-2025-3776 2 - CVE-2024-26809 3 - CVE-2025-46337 4 - CVE-2025-26529 5 - CVE-2025-32433 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    4 May 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE-2025-46337 ⚠️🔴 CRITICAL (10) 🏢 ADOdb - ADOdb 🏗️ < 5.22.9 🔗 https://t.co/50YmRX4hcn 🔗 https://t.co/URfDiMYiYk 🔗 https://t.co/FXJfljkCuu #CyberCron #VulnAlert #InfoSec https://t.co/4WJdQxuuwL

    @cybercronai

    3 May 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2025-46337 ⚠️🔴 CRITICAL (10) 🏢 ADOdb - ADOdb 🏗️ < 5.22.9 🔗 https://t.co/50YmRX4hcn 🔗 https://t.co/URfDiMYiYk 🔗 https://t.co/FXJfljkCuu #CyberCron #VulnAlert #InfoSec https://t.co/KP0XCVxmlI

    @cybercronai

    2 May 2025

    1870 Impressions

    3 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  9. ⚠️Múltiples vulnerabilidades del kernel de Linux Red Hat ❗CVE-2025-46337 ❗CVE-2025-21927 ❗CVE-2025-22869 ❗CVE-2025-30204 ❗CVE-2025-24209 ➡️Más info: https://t.co/T4ViIi50N9 https://t.co/rpOVorctqA

    @CERTpy

    2 May 2025

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-46337 ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query … https://t.co/HMN707zXUO

    @CVEnew

    1 May 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. [CVE-2025-46337: CRITICAL] Vulnerable ADOdb versions allowed SQL injection via pg_insert_id(). Make sure to update to version 5.22.9 to stay protected against cyber attacks. #cybersecurity#cve,CVE-2025-46337,#cybersecurity https://t.co/XieGJGeJDk https://t.co/HodoHUFcgr

    @CveFindCom

    1 May 2025

    21 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes