Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain administrative access.
Metrics
Affected Vendors & Products
References
History
Sun, 12 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adianti Framework 5.5.0 and 5.6.0 contains an SQL injection vulnerability that allows authenticated users to manipulate database queries by injecting SQL code through the name field in SystemProfileForm. Attackers can submit crafted SQL statements in the profile edit endpoint to modify user credentials and gain administrative access. | |
| Title | Adianti Framework 5.5.0 and 5.6.0 SQL Injection via Profile | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-12T12:28:43.786Z
Reserved: 2026-04-12T12:09:59.724Z
Link: CVE-2018-25257
No data.
Status : Received
Published: 2026-04-12T13:16:31.567
Modified: 2026-04-12T13:16:31.567
Link: CVE-2018-25257
No data.
OpenCVE Enrichment
No data.