{"id":"CVE-2025-3818","details":"A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.","modified":"2026-04-10T05:26:01.266758Z","published":"2025-04-19T20:15:15Z","references":[{"type":"WEB","url":"https://noppgwz8if.feishu.cn/docx/TxjpddUpTokyBwxibSgcTRr7nUf"},{"type":"WEB","url":"https://vuldb.com/?ctiid.305724"},{"type":"WEB","url":"https://vuldb.com/?id.305724"},{"type":"WEB","url":"https://vuldb.com/?submit.555649"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00041.html"}],"schema_version":"1.7.5"}