CVE-2018-25175
Published: 06 March 2026
Summary
CVE-2018-25175 is a high-severity SQL Injection (CWE-89) vulnerability. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 16.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SI-10 (Information Input Validation).
Deeper analysis
CVE-2018-25175 is an SQL injection vulnerability (CWE-89) affecting Alienor Web Libre 2.0. The flaw resides in the identifiant parameter of the index.php script, where insufficient input sanitization allows attackers to inject and execute arbitrary SQL queries.
Unauthenticated remote attackers can exploit this vulnerability by submitting crafted POST requests to index.php with SQL injection payloads in the identifiant field. Successful exploitation enables extraction of sensitive database information, including usernames, databases, and version details. The CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) reflects network accessibility with low complexity, no privileges or user interaction required, high confidentiality impact, low integrity impact, and no availability impact.
Advisories and exploit details are documented at https://www.vulncheck.com/advisories/alienor-web-libre-sql-injection-via-indexphp and https://www.exploit-db.com/exploits/45827, which include a proof-of-concept for the SQL injection via the identifiant parameter. No specific patches are detailed in the provided information.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2018-21630
Vulnerability details
Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the identifiant parameter. Attackers can submit crafted POST requests to index.php with SQL injection payloads in the…
more
identifiant field to extract sensitive database information including usernames, databases, and version details.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
SQL injection in public-facing web application (index.php) enables exploitation of public-facing application (T1190) and facilitates arbitrary database queries for sensitive information extraction (T1213.006).
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces input validation mechanisms at entry points to sanitize the identifiant parameter and prevent SQL injection payloads from executing arbitrary queries.
Requires identification, reporting, and timely correction of flaws like the SQL injection vulnerability in index.php to eliminate the root cause.
Implements vulnerability scanning to identify SQL injection issues such as CVE-2018-25175 in web applications like Alienor Web Libre.