CVE-2025-5878 describes a problematic vulnerability in the ESAPI esapi-java-legacy library, specifically within the Encoder.encodeForSQL interface, which can lead to improper neutralization of special elements. This issue allows for remote attacks and has publicly disclosed exploit details. With a CVSS score of 7.3 (HIGH), the vulnerability has a low attack complexity and can result in limited impact to confidentiality, integrity, and availability. While an exploit has been disclosed, there is no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ESAPI | Esapi-Java-Legacy | 2.0-rc10, 2.0-rc11, 2.0.1, 2.0GA1, 2.1.0, 2.1.0.1, 2.2.0.0, 2.2.0.0-RC1, 2.2.0.0-RC2, 2.2.0.0-RC3, 2.2.1.0, 2.2.1.0-RC1, 2.2.1.1, 2.2.2.0, 2.2.3.0, 2.2.3.1, 2.3.0.0, 2.4.0.0, 2.5.0.0, 2.5.1.0, 2.5.2.0, 2.5.3.0, 2.5.3.1, 2.5.4.0, 2.5.5.0, 2.6.0.0, 2.6.1.0, 2.6.2.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.