CVE-2025-25181: Advantive VeraCore SQL Injection Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-03-10. EPSS: 55.5% chance of exploitation in the next 30 days.
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
Affected products
- Advantive VeraCore: before 2025.1.1.3 (fixed in 2025.1.1.3)
Published 2025-02-03. Last modified 2026-06-17.