LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2018-25171

CVE-2018-25171 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: March 6, 2026

EdTv - SQL Injection

Published: March 6, 2026Updated: March 6, 2026Remote Exploitable

Overview

EdTv 2 contains an sql injection caused by unsanitized 'id' parameter in admin/edit_source endpoint, letting unauthenticated attackers execute arbitrary SQL queries and extract database information, exploit requires crafted GET requests.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can execute arbitrary SQL queries to extract sensitive database information, compromising data confidentiality and integrity.

Mitigation

Update to the latest version with SQL injection fixes.

Details

CVE ID
CVE-2018-25171
Severity
High
CVSS Score
8.2
Type
sql_injection
Status
new

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N