ZeroHour

CVE-2025-25181

KEV PoC ×2niche

Actively Exploited SQL Injection in Advantive VeraCore timeoutWarning.asp

CISA: Advantive VeraCore SQL Injection Vulnerability

CVSS 3.1
7.5 high
EPSS
57%p99
Published
()
KEV added
AI analysis

CVE-2025-25181 is a SQL injection vulnerability in the timeoutWarning.asp page of Advantive VeraCore, affecting versions through 2025.1.0, in which the unauthenticated PmSess1 parameter is incorporated into a database query without proper sanitization. An attacker triggers it by sending a crafted PmSess1 value in a network request to timeoutWarning.asp, with no credentials or user interaction required. Successful exploitation allows execution of arbitrary SQL commands, with high confidentiality impact — an attacker can read, and potentially manipulate, data in the VeraCore database. Organizations running VeraCore are affected, particularly fulfillment and 3PL providers whose VeraCore web application is exposed to the internet. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-10, and reporting indicates the XE Group exploited it (alongside CVE-2024-57968) for years before it was patched.

What to do: Upgrade VeraCore to a fixed release per Advantive's guidance (all versions through 2025.1.0 are affected); as an interim measure, restrict internet exposure of the VeraCore web application and review web-server logs for anomalous PmSess1 values, unusual SQL errors, or unexpected requests to timeoutWarning.asp. Organizations should hunt for signs of compromise given reports of multi-year exploitation by XE Group, including use of the related CVE-2024-57968, and federal agencies must apply mitigations per CISA BOD 22-01 timelines.

Affected
Advantive VeraCorethrough 2025.1.0 (inclusive)
Estimated exposure
nichelikely hundreds to low thousands of deployments at fulfillment/3PL and e-commerce operations (no public scan or install counts available) — VeraCore is specialized warehouse-management/order-fulfillment software sold to a limited customer base, and no public install counts or internet-exposure scan data were provided, so this is a deployment-pattern estimate only.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

CISA Known Exploited Vulnerability
Affected
Advantive VeraCore
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
advantive
Products
veracore
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news