SQL injection vulnerability in Advantive VeraCore's timeoutWarning.asp allows remote attackers to execute arbitrary SQL commands without authentication. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-02-03
Added to CISA KEV: 2025-03-10 35 DAYS BETWEEN CVE AND KEV
CVE-2025-25181 is a SQL injection vulnerability affecting Advantive VeraCore, an order fulfillment and warehouse management software platform?id=CVE-2025-25181?kagi_q=CVE-2025-25181+details [3].
CVE-2025-25181 Detail Description A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter. ... Description. A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore…
Description This signature detects attempts to exploit a SQL injection vulnerability in Advantive VeraCore.
CVE-2025-25181 is a SQL Injection vulnerability affecting Advantive VeraCore, which is an order fulfillment and warehouse management software.