GHSA-8x27-jwjr-8545
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Quick fix
GHSA-8x27-jwjr-8545 — adodb/adodb-php: upgrade to the fixed version with the command below.
composer require adodb/adodb-php:^5.22.9Details
Improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id() with user-supplied data.
Note that the indicated Severity corresponds to a worst-case usage scenario.
### Impact PostgreSQL drivers (postgres64, postgres7, postgres8, postgres9).
### Patches Vulnerability is fixed in ADOdb 5.22.9 (11107d6d6e5160b62e05dff8a3a2678cf0e3a426).
### Workarounds Only pass controlled data to pg_insert_id() method's $fieldname parameter, or escape it with pg_escape_identifier() first.
### References - Issue https://github.com/ADOdb/ADOdb/issues/1070 - [Blog post](https://xaliom.blogspot.com/2025/05/from-sast-to-cve-2025-46337.html) by Marco Nappi
### Credits Thanks to Marco Nappi (@mrcnpp) for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 5.22.9composer require adodb/adodb-php:^5.22.9References
- https://github.com/ADOdb/ADOdb/security/advisories/GHSA-8x27-jwjr-8545[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-46337[ADVISORY]
- https://github.com/ADOdb/ADOdb/issues/1070[WEB]
- https://github.com/ADOdb/ADOdb/commit/11107d6d6e5160b62e05dff8a3a2678cf0e3a426[WEB]
- https://github.com/ADOdb/ADOdb[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/05/msg00029.html[WEB]
- https://xaliom.blogspot.com/2025/05/from-sast-to-cve-2025-46337.html[WEB]