SQL Injection Vulnerability in ADOdb PHP Database Class Library
CVE-2025-54119
What is CVE-2025-54119?
The ADOdb PHP database class library is affected by a vulnerability that arises from improper escaping of query parameters. This can lead to the execution of arbitrary SQL statements when an attacker interacts with a sqlite3 database through specific methods such as metaColumns(), metaForeignKeys(), or metaIndexes(). The issue primarily exists in versions 5.22.9 and earlier, where passing an unvalidated or malicious table name can compromise the database's integrity. A fix is available in version 5.22.10, and developers are advised to ensure that only controlled data is supplied to these method parameters to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ADOdb < 5.22.10
References
CVSS V3.1
Timeline
Vulnerability published
