CVE-2018-25175
Published: 06 March 2026
Description
Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the identifiant parameter. Attackers can submit crafted POST requests to index.php with SQL injection payloads in the…
more
identifiant field to extract sensitive database information including usernames, databases, and version details.
Mitigating Controls (NIST 800-53 r5)AI
Directly enforces input validation mechanisms at entry points to sanitize the identifiant parameter and prevent SQL injection payloads from executing arbitrary queries.
Requires identification, reporting, and timely correction of flaws like the SQL injection vulnerability in index.php to eliminate the root cause.
Implements vulnerability scanning to identify SQL injection issues such as CVE-2018-25175 in web applications like Alienor Web Libre.
Security SummaryAI
CVE-2018-25175 is an SQL injection vulnerability (CWE-89) affecting Alienor Web Libre 2.0. The flaw resides in the identifiant parameter of the index.php script, where insufficient input sanitization allows attackers to inject and execute arbitrary SQL queries.
Unauthenticated remote attackers can exploit this vulnerability by submitting crafted POST requests to index.php with SQL injection payloads in the identifiant field. Successful exploitation enables extraction of sensitive database information, including usernames, databases, and version details. The CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) reflects network accessibility with low complexity, no privileges or user interaction required, high confidentiality impact, low integrity impact, and no availability impact.
Advisories and exploit details are documented at https://www.vulncheck.com/advisories/alienor-web-libre-sql-injection-via-indexphp and https://www.exploit-db.com/exploits/45827, which include a proof-of-concept for the SQL injection via the identifiant parameter. No specific patches are detailed in the provided information.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
SQL injection in public-facing web application (index.php) enables exploitation of public-facing application (T1190) and facilitates arbitrary database queries for sensitive information extraction (T1213.006).