CVE-2025-25226

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 89

Summary

CVE-2025-25226 is a SQL injection vulnerability affecting the quoteNameStr method of a database package. The issue arises due to improper handling of identifiers. Notably, this protected method, which is not used in the original packages of the 2.x and 3.x branches, poses no risk when using the standard database class. However, classes that extend the affected class and utilize the vulnerable method may be susceptible to exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share