Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-3818

Опубликовано: 19 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.5
CVSS3: 6.3

Описание

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps-legacy/xenial

released

1:0.37+20120626-1ubuntu0.1~esm1
esm-apps/bionic

released

1:0.38+20170615-1ubuntu0.1~esm1
esm-apps/focal

released

1:0.40-2ubuntu0.1~esm1
esm-apps/jammy

released

1:0.61-1ubuntu0.1~esm1
esm-apps/noble

released

1:0.62-4ubuntu0.1~esm1
esm-apps/resolute

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
focal

ignored

end of standard support, was needs-triage
jammy

needed

Показывать по

EPSS

Процентиль: 23%
0.00311
Низкий

6.5 Medium

CVSS2

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
debian
больше 1 года назад

A vulnerability, which was classified as critical, was found in webpy ...

CVSS3: 6.3
github
больше 1 года назад

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость функции PostgresDB._process_insert_query() (file web/db.py) веб-фреймворка создания веб-приложений web.py, позволяющая нарушителю выполнить произвольные SQL-команды

EPSS

Процентиль: 23%
0.00311
Низкий

6.5 Medium

CVSS2

6.3 Medium

CVSS3