{"id":"CVE-2025-3818","details":"A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.","modified":"2026-01-27T04:20:01.623580Z","published":"2025-04-19T20:15:15Z","withdrawn":"2026-01-27T04:20:01.623580Z","references":[{"type":"WEB","url":"https://noppgwz8if.feishu.cn/docx/TxjpddUpTokyBwxibSgcTRr7nUf"},{"type":"WEB","url":"https://vuldb.com/?ctiid.305724"},{"type":"WEB","url":"https://vuldb.com/?id.305724"},{"type":"WEB","url":"https://vuldb.com/?submit.555649"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00041.html"}],"schema_version":"1.7.3"}