CVE-2025-10878Disclosure(omran / fikir_odalari_adminpando)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch omran fikir_odalari_adminpando systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full administrative access to the application, including the ability to manipulate the public-facing website content (HTML/DOM manipulation).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fikir_odalari_adminpando

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-02-03)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fikir_odalari_adminpando

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-01-29: 1Mentions · 2026-02-03: 4PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-02-03: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 401-2902-03
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-291
PoC1
2026-02-034
Disclosure3Patch1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-10878 A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerab… https://www.cve.org/CVERecord?id=CVE-2025-10878

    Post summary

    The text announces a SQL injection vulnerability in the login function of Fikir Odalari AdminPando 1.0.1, providing basic technical details but no PoC, exploit code, active exploitation evidence, or patch information.

    01020357
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2025-10878 PoC for CVE-2025-10878 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-10878

    Post summary

    The notice confirms that a proof of concept exists for CVE‑2025‑10878 and provides a link to a vulnerability details page.

    01000120
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-10878: CRITICAL] SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 pre-2026 allows attackers to bypass login, gain admin access, and manipulate website content. Immediate update recomme...#cve,CVE-2025-10878,#cybersecurity https://cvefind.com/CVE-2025-10878

    Post summary

    The post announces a critical SQL injection flaw in AdminPando 1.0.1, urges an immediate patch, and details the impact.

    0000064
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-10878 - Critical A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, ... https://www.thehackerwire.com/vulnerability/CVE-2025-10878/ https://t.co/yMsMwfr3rm

    Post summary

    CVE-2025-10878 is a SQL injection vulnerability affecting Fikir Odalari AdminPando 1.0.1, disclosed with technical details but no PoC or evidence of exploitation.

    0000049
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-10878: Insaat (CVSS: 10.0)... Basic login param SQLi in AdminPando 1.0.1 offers full admin access without authentication—trivial to exploit for compl... https://zerodaysignal.com/vulnerability/CVE-2025-10878 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2025-10878, a critical SQL injection in AdminPando 1.0.1 with CVSS 10.0, and links to a vulnerability page but provides no details on active exploitation, patches, or a PoC.

    0000047
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appomranfikir_odalari_adminpando---

Explore more