{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-01T09:21:00.035","vulnerabilities":[{"cve":{"id":"CVE-2025-46337","sourceIdentifier":"security-advisories@github.com","published":"2025-05-01T18:15:57.510","lastModified":"2026-06-17T09:26:15.620","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data. This issue has been patched in version 5.22.9."},{"lang":"es","value":"ADOdb es una librería de clases de bases de datos PHP que proporciona abstracciones para realizar consultas y administrar bases de datos. Antes de la versión 5.22.9, el escape incorrecto de un parámetro de consulta podía permitir que un atacante ejecutara sentencias SQL arbitrarias cuando el código que usa ADOdb se conecta a una base de datos PostgreSQL e invoca pg_insert_id() con datos proporcionados por el usuario. Este problema se ha corregido en la versión 5.22.9."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"ADOdb","product":"ADOdb","versions":[{"version":"< 5.22.9","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-02T17:57:27.460605Z","id":"CVE-2025-46337","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/ADOdb/ADOdb/commit/11107d6d6e5160b62e05dff8a3a2678cf0e3a426","source":"security-advisories@github.com"},{"url":"https://github.com/ADOdb/ADOdb/issues/1070","source":"security-advisories@github.com"},{"url":"https://github.com/ADOdb/ADOdb/security/advisories/GHSA-8x27-jwjr-8545","source":"security-advisories@github.com"},{"url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00029.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://xaliom.blogspot.com/2025/05/from-sast-to-cve-2025-46337.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}