Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094
Summary
Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The PostgreSQL Global Development Group (also known as Postgres) has released an advisory to address a high severity vulnerability in PostgreSQL. PostgreSQL is a relational SQL database management system.
CVE-2025-1094 is an 'improper neutralisation of quoting syntax' vulnerability with a CVSSv3 score of 8.1. A remote unauthenticated attacker could execute arbitrary code with the privileges of the current site user by sending a specially crafted SQL statement. When exploited on a remote access agent, an attacker may achieve remote code execution.
Proof-of-concept code has been released for CVE-2025-1094.
Threat updates
Remediation advice
Affected organisations are encouraged to review PostgreSQL's CVE-2025-1094 security advisory and apply the relevant updates as soon as practicable.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 21 February 2025 1:08 pm