CVE-2018-25257: Adianti Framework
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain administrative access.
Affected products
- Adianti Adianti Framework: version 5.5.0 only
Published 2026-04-12. Last modified 2026-06-17.