CVE-2025-25181
KEV PoC ×2nicheActively Exploited SQL Injection in Advantive VeraCore timeoutWarning.asp
CISA: Advantive VeraCore SQL Injection Vulnerability
CVE-2025-25181 is a SQL injection vulnerability in the timeoutWarning.asp page of Advantive VeraCore, affecting versions through 2025.1.0, in which the unauthenticated PmSess1 parameter is incorporated into a database query without proper sanitization. An attacker triggers it by sending a crafted PmSess1 value in a network request to timeoutWarning.asp, with no credentials or user interaction required. Successful exploitation allows execution of arbitrary SQL commands, with high confidentiality impact — an attacker can read, and potentially manipulate, data in the VeraCore database. Organizations running VeraCore are affected, particularly fulfillment and 3PL providers whose VeraCore web application is exposed to the internet. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-10, and reporting indicates the XE Group exploited it (alongside CVE-2024-57968) for years before it was patched.
What to do: Upgrade VeraCore to a fixed release per Advantive's guidance (all versions through 2025.1.0 are affected); as an interim measure, restrict internet exposure of the VeraCore web application and review web-server logs for anomalous PmSess1 values, unusual SQL errors, or unexpected requests to timeoutWarning.asp. Organizations should hunt for signs of compromise given reports of multi-year exploitation by XE Group, including use of the related CVE-2024-57968, and federal agencies must apply mitigations per CISA BOD 22-01 timelines.
| Advantive VeraCore | through 2025.1.0 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
- Affected
- Advantive VeraCore
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- advantive
- Products
- veracore
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N