Junglewise Threat Intelligence

CVE-2025-25181: Advantive VeraCore SQL Injection Vulnerability

CVE-2025-25181 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2025-03-10

Executive brief

Advantive VeraCore contains a SQL injection vulnerability in the timeoutWarning.asp component. Remote attackers can execute arbitrary SQL commands by manipulating the PmSess1 parameter, potentially leading to unauthorized data access or modification.

Affected products

  • Advantive VeraCore through 2025.1.0

Timeline

  • 2025-02-03: disclosed: CVE published and initial analysis received from MITRE
  • 2025-03-10: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-03-10: advisory: NVD publication date

Related threats