Description

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a sqlite3 database and calls the metaColumns(), metaForeignKeys() or metaIndexes() methods with a crafted table name. This is fixed in version 5.22.10. To workaround this issue, only pass controlled data to metaColumns(), metaForeignKeys() and metaIndexes() method's $table parameter.

INFO

Published Date :

2025-08-05T00:12:52.505Z

Last Modified :

2025-11-03T17:45:02.291Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-54119 vulnerability.

Vendors Products
Adodb Lite
  • Adodb Lite
Adodb Project
  • Adodb

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact