


Perceptive Security
SOC/SIEM Consultancy

EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'i…
Published:
5 March 2026 at 23:00:00
Alert date:
6 March 2026 at 14:08:47
Source:
nvd.nist.gov
Web Technologies, Database & Storage
EdTv 2 contains a critical SQL injection vulnerability in the 'id' parameter that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can exploit this by sending GET requests to the admin/edit_source endpoint with crafted SQL UNION statements. The vulnerability enables extraction of sensitive database information including schema names, user credentials, and version details. This represents a high-severity security flaw that could lead to complete database compromise. The vulnerability affects EdTv version 2 and has been assigned CVE-2018-25171.
Technical details
Mitigation steps:
Affected products:
EdTv 2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25171
https://www.exploit-db.com/exploits/45849
https://www.vulncheck.com/advisories/edtv-sql-injection-via-id-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
