Executive brief
Advantive VeraCore contains a SQL injection vulnerability in the timeoutWarning.asp component. Remote attackers can execute arbitrary SQL commands by manipulating the PmSess1 parameter, potentially leading to unauthorized data access or modification.
Affected products
- Advantive VeraCore through 2025.1.0
Timeline
- 2025-02-03: disclosed: CVE published and initial analysis received from MITRE
- 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-03-10: advisory: NVD publication date