CVE-2018-25171 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 6, 2026
EdTv - SQL Injection
Published: March 6, 2026Updated: March 6, 2026Remote Exploitable
Overview
EdTv 2 contains an sql injection caused by unsanitized 'id' parameter in admin/edit_source endpoint, letting unauthenticated attackers execute arbitrary SQL queries and extract database information, exploit requires crafted GET requests.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Unauthenticated attackers can execute arbitrary SQL queries to extract sensitive database information, compromising data confidentiality and integrity.
Mitigation
Update to the latest version with SQL injection fixes.
References
Related Resources
Details
- CVE ID
- CVE-2018-25171
- Severity
- High
- CVSS Score
- 8.2
- Type
- sql_injection
- Status
- new
CWE
- CWE-434
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N