CVE-2018-25428
📛 CVE Title
(no title)
Description
Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 8.2 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N- Effective score
- 8.2 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2018-25428
- Linked Threat
- CVE-2018-25428 — CVE-2018-25428
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-06-01 22:16:15 UTC
- NVD last modified
- 2026-07-22 08:10:00 UTC
- NVD CVSS v3.1
- 8.2 / 10 HIGH source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 4.2 / 10
- EPSS score
- 0.0034 (probability of exploitation in next 30 days)
- EPSS percentile
- 26.60% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27
NVD-assigned CWE(s):
CWE-89
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-07-27 22:13 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2018-21949 - Assigner
- VulnCheck
- Published
- Jun 1, 2026, 9:00:19 PM
- Updated
- Jun 2, 2026, 3:47:20 PM
- EUVD base score (CVSS 4.0)
-
8.8 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.3400
- Vendors
- Paroiciel
- Products
-
Paroiciel (11.20)
- Aliases
-
GHSA-c2wr-3mhp-wpjm
ENISA description: Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://datapacket.dl.sourceforge.net/project/paroiciel/version%2011/par6lus_11_20160225.exe tenable:datapacket.dl.sourceforge.net
- https://nvd.nist.gov/vuln/detail/CVE-2018-25428 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2018-25428 tenable:www.cve.org
- https://www.exploit-db.com/exploits/45810 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.paroiciel.com/ tenable:www.paroiciel.com
- https://www.vulncheck.com/advisories/paroiciel-sql-injection-via-trecidliste-parameter tenable:www.vulncheck.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://datapacket.dl.sourceforge.net/project/paroiciel/version%2011/par6lus_11_20160225.exe disclosure@vulncheck.com
- https://www.exploit-db.com/exploits/45810 disclosure@vulncheck.com
- https://www.paroiciel.com/ disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/paroiciel-sql-injection-via-trecidliste-parameter disclosure@vulncheck.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:dbsguru.com
Oracle Critical Database Patch ID for January 2025 along with enabled Download Link An Essential/Critical Patch Update could be a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and third-party elements enclosed in Oracle merchandise. These patches are sometimes additive, however every informative describes only the protection ...
2026-06-19 02:32 UTC -
web:dbsguru.com
Oracle Critical Database Patch ID for July 2025 along with enabled Download Link An Essential/Critical Patch Update could be a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and third-party elements enclosed in Oracle merchandise. These patches are sometimes additive, however, every informative describes only the protection ...
2026-06-19 02:32 UTC -
web:experienceleague.adobe.com
The Adobe Commerce security patch release notes provide information about the latest security improvements for supported versions of Adobe Commerce. About security patch releases Security Bug Fix : A software code change that resolves an identified security issue and delivers expected results in an affected product area.
2026-06-19 02:32 UTC -
web:helpx.adobe.com
This page contains important information regarding security vulnerabilities that could affect specific versions of Adobe products. Use this information to take the prescribed corrective actions.
2026-06-19 02:32 UTC -
web:knowledge.broadcom.com
The intent of this article is to help customers that are using VMware vSphere 8.x address the most critical security vulnerabilities. Broadcom will provide all perpetual license customers, including those that have expired support contracts, with access to zero-day security patches, which are defined by Broadcom as patches for Critical Severity Security Alerts with a Common Vulnerability ...
2026-06-19 02:32 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-19 02:32 UTC -
web:support.microsoft.com
Improvements and fixes This security update introduces the SharePoint Server Subscription Edition Version 26H1 feature update. This feature update will be included in all SharePoint Server Subscription Edition public updates going forward. For more information about this feature update, see New and improved features in SharePoint Server Subscription Edition Version 26H1. This link may be ...
2026-06-19 02:32 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-06-19 02:32 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-06-19 02:32 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-19 02:32 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.