Medium severity5.8CISA KEVNVD Advisory· Published Feb 3, 2025· Updated Jun 17, 2026
CVE-2025-25181
CVE-2025-25181
Description
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- intezer.com/blog/research/xe-group-exploiting-zero-days/nvdExploitTechnical DescriptionThird Party Advisory
- www.solissecurity.com/en-us/insights/xe-group-from-credit-card-skimming-to-exploiting-zero-days/nvdExploitTechnical DescriptionThird Party Advisory
- advantive.my.site.com/support/s/knowledgenvdProductRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.