- Description
- A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an exploit has been disclosed to the public. The project was contacted early about this issue and handled it with an exceptional level of professionalism. Upgrading to version 2.7.0.0 is able to address this issue. Commit ID f75ac2c2647a81d2cfbdc9c899f8719c240ed512 is disabling the feature by default and any attempt to use it will trigger a warning. And commit ID e2322914304d9b1c52523ff24be495b7832f6a56 is updating the misleading Java class documentation to warn about the risks.
- Source
- cna@vuldb.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 6.9
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 7.3
- Impact score
- 3.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- cna@vuldb.com
- CWE-20
- Hype score
- Not currently trending
Identificador de vulnerabilidad CVE-2025-5878. 👉 https://t.co/UnRLp7cupd https://t.co/VKib9yO5NH
@EnigmaSecurity_
29 Jun 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Identificador de vulnerabilidad CVE-2025-5878. 👉 https://t.co/fw1g5RTDj1 https://t.co/4gqSoToC69
@EnigmaSecurity_
29 Jun 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Identificador de vulnerabilidad CVE-2025-5878. 👉 https://t.co/iAGeF9Gvfw https://t.co/v3ytiqLh5L
@EnigmaSecurity_
29 Jun 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔍 **Vulnerability Identifier CVE-2025-5878** 🛡️ (Plain text output as requested.) 👉 https://t.co/iAGeF9Gvfw https://t.co/JRHFMF0akh
@EnigmaSecurity_
29 Jun 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Identificación de vulnerabilidad CVE-2025-5878 en sistemas técnicos. 👉 https://t.co/Zt1n5qpfhg https://t.co/irLyqpoi7z
@EnigmaSecurity_
29 Jun 2025
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Identificador de vulnerabilidad CVE-2025-5878. 👉 https://t.co/aNQMT2EYlg https://t.co/jHm4PMCzLc
@EnigmaSecurity_
29 Jun 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔍 **Vulnerability Identifier CVE-2025-5878** 🛡️ (Plain text output only, as requested.) Let me know if you'd like any additional details! 😊 👉 https://t.co/aNQMT2EYlg https://t.co/vdhB5LfTzY
@EnigmaSecurity_
29 Jun 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-5878 SQL Injection Vulnerability in ESAPI Java Legacy Encoder Interface https://t.co/msUG4ugwst
@VulmonFeeds
29 Jun 2025
97 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-5878 A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. … https://t.co/xWqz4gNePK
@CVEnew
29 Jun 2025
603 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes