CVE-2018-25180Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the mailid parameter in outmail and inmail modules. Attackers can also download the SQLite database file directly from the application directory to extract sensitive mail tracking data and credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Technical Details · 2026-03-06: 103-0603-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2018-25180 - Salzertechnologies - Maitra - https://www.redpacketsecurity.com/cve-alert-cve-2018-25180-salzertechnologies-maitra/ #OSINT #ThreatIntel #CyberSecurity #cve-2018-25180 #salzertechnologies #maitra

    Post summary

    The text serves as a CVE alert, directing readers to an external article for details about CVE‑2018‑25180.

    00000105
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2018-25180 Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the mail… https://www.cve.org/CVERecord?id=CVE-2018-25180

    Post summary

    The text provides a concise disclosure of an SQL injection vulnerability in Maitra 1.7.2 that permits authenticated attackers to run arbitrary SQL commands through mail input.

    0000098
    56.6K followersView on X

Explore more