CVE-2018-25205 describes an SQL injection vulnerability in ASP.NET jVideo Kit 1.0, allowing unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Rated 8.2 High (CVSS), this vulnerability permits remote exploitation with low complexity, enabling the extraction of sensitive database information via GET or POST requests. Despite its severity, there is no evidence of active exploitation, public exploit code (e.g., Metasploit, Nuclei, ExploitDB), or community discussion. Its extremely low EPSS score further suggests minimal real-world risk at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mediasoftpro | ASP.NET JVideo Kit | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.