Description
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a sqlite3 database and calls the metaColumns(), metaForeignKeys() or metaIndexes() methods with a crafted table name. This is fixed in version 5.22.10. To workaround this issue, only pass controlled data to metaColumns(), metaForeignKeys() and metaIndexes() method's $table parameter.
INFO
Published Date :
2025-08-05T00:12:52.505Z
Last Modified :
2025-11-03T17:45:02.291Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-54119 vulnerability.
| Vendors | Products |
|---|---|
| Adodb Lite |
|
| Adodb Project |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-54119.