Known Exploited Vulnerabilities CVE-2025-25181

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2025-25181 Advantive VeraCore SQL Injection Vulnerability exploitation_technique T1055 Process Injection
Comments
This vulnerability exists in the timeoutwarning.asp file in VeraCore versions up to 2025.1.0 and allows an attacker to execute commands due to a lack of proper input sanitization, leading to effects such as privilege escalation and data destruction.
References
CVE-2025-25181 Advantive VeraCore SQL Injection Vulnerability exploitation_technique T1068 Exploitation for Privilege Escalation
Comments
This vulnerability exists in the timeoutwarning.asp file in VeraCore versions up to 2025.1.0 and allows an attacker to execute commands due to a lack of proper input sanitization, leading to effects such as privilege escalation and data destruction.
References
CVE-2025-25181 Advantive VeraCore SQL Injection Vulnerability primary_impact T1485 Data Destruction
Comments
This vulnerability exists in the timeoutwarning.asp file in VeraCore versions up to 2025.1.0 and allows an attacker to execute commands due to a lack of proper input sanitization, leading to effects such as privilege escalation and data destruction.
References