CVE-2025-5878 Details
Description
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an exploit has been disclosed to the public. The project was contacted early about this issue and handled it with an exceptional level of professionalism. Upgrading to version 2.7.0.0 is able to address this issue. Commit ID f75ac2c2647a81d2cfbdc9c899f8719c240ed512 is disabling the feature by default and any attempt to use it will trigger a warning. And commit ID e2322914304d9b1c52523ff24be495b7832f6a56 is updating the misleading Java class documentation to warn about the risks.
A vulnerability allowing SQL injection defense bypass has been identified in the ESAPI library, specifically in the 'esapi-java-legacy' version 2.6.2.0 and prior. The issue arises within the SQL Injection Defense feature, particularly the 'Encoder.encodeForSQL' method. This vulnerability allows attackers to exploit improper handling of special characters, potentially leading to SQL injection attacks. The vulnerability can be exploited remotely, without authentication.
Upgrading to ESAPI version 2.7.0.0 addresses this vulnerability. The updated version is available on the ESAPI GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2025CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/07/msg00010.html | CVE | |
| https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/ESAPI-security-bulletin13.pdf | [email protected] | AdvisoryPermission RequiredVendor |
| https://github.com/ESAPI/esapi-java-legacy/commit/e2322914304d9b1c52523ff24be495b7832f6a56 | [email protected] | Source CodeVendor |
| https://github.com/ESAPI/esapi-java-legacy/commit/f75ac2c2647a81d2cfbdc9c899f8719c240ed512 | [email protected] | Source CodeVendor |
| https://github.com/ESAPI/esapi-java-legacy/releases/tag/esapi-2.7.0.0 | [email protected] | Release NotesVendor |
| https://github.com/uglory-gll/javasec/blob/main/ESAPI.md | [email protected] | Not Applicable |
| https://vuldb.com/?ctiid.314321 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.314321 | [email protected] | AdvisoryBundleRemedy |
| https://vuldb.com/?submit.590149 | [email protected] | Technical Description |
| https://vuldb.com/?submit.590150 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-138 | Improper Neutralization of Special Elements | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ESAPI esapi-java-legacy | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Jun 29, 2025 | New CVE Received | [email protected] |
Volerion