VDB
CVE-2025-3818
CVE-2025-3818
PUBLISHED
CVSS 6.300000190734863 MEDIUM
A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
EPSS 0.33% · 25.8th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.33%
25.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| webpy | web.py | 0.70 |
Timeline
- Apr 19, 2025 Coalition ESS Score
- Apr 19, 2025 CVE Published
- Apr 19, 2025 PoC Published
- Apr 20, 2025 EPSS Score
- Apr 20, 2025 PoC Published
- Apr 21, 2025 Coalition ESS Score
- May 3, 2025 EPSS Score
- May 15, 2025 EPSS Score
- May 28, 2025 EPSS Score
- May 29, 2025 Coalition ESS Score
- May 29, 2025 CVE Updated
- Jun 9, 2025 EPSS Score
References
- https://lists.debian.org/debian-lts-announce/2025/05/msg00041.html advisory
- VDB-305724 | webpy web.py db.py PostgresDB._process_insert_query sql injection vdb
- VDB-305724 | CTI Indicators (IOB, IOC, TTP, IOA) url
- Submit #555649 | web.py 0.70 SQL Injection third-party-advisory
- https://noppgwz8if.feishu.cn/docx/TxjpddUpTokyBwxibSgcTRr7nUf exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-3818 advisory