Back to Database
Status published
Critical
CVE-2025-58448
rAthena has SQL Injection in PartyBooking component via `WorldName` parameter.
Vulnerability Description
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking component via `WorldName` parameter. Commit 0d89ae0 fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58448
Credits & Attribution
No credits recorded in the NVD database.
References
More from rathena
View All →CVE-2025-62797
CSRF in FluxCP account endpoints allows account takeover / state-changing actions
High
8.6
CVE-2025-62170
rAthena map-server use-after-free vulnerability in RODEX
High
7.5
CVE-2025-58750
rAthena missing bound check in chclif_parse_moveCharSlot
High
8.2
CVE-2025-58447
rAthena has heap-based buffer overflow in login server
Critical
9.8
CVE-2024-45799
Javascript Injection in Vending Info/Buyers Info Module in FluxCP
High
7.3
Affected Vendor
rathena
View all reports →Affected Software
rathena
Vulnerable Versions:
< 0d89ae0
Timeline
Official Publish:
September 9th, 2025
Last Modified:
September 10th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N