We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46337

SQL injection in ADOdb PostgreSQL driver pg_insert_id() method



Description

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9.

Reserved 2025-04-22 | Published 2025-05-01 | Updated 2025-05-26 | Assigner GitHub_M


CRITICAL: 10.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Problem types

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

< 5.22.9
affected

References

github.com/.../ADOdb/security/advisories/GHSA-8x27-jwjr-8545

github.com/ADOdb/ADOdb/issues/1070

github.com/...ommit/11107d6d6e5160b62e05dff8a3a2678cf0e3a426

cve.org (CVE-2025-46337)

nvd.nist.gov (CVE-2025-46337)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46337

Support options

Helpdesk Chat, Email, Knowledgebase