CVE-2025-30714

Executive Summary

CVE-2025-30714 exposes a vulnerability in Oracle MySQL Connector/Python (v9.0.0‑9.2.0). A low‑privileged attacker with network access can exploit the flaw via multiple protocols, but human interaction from a non‑attacker is required. Successful exploitation can lead to unauthorized access to critical data or full compromise of all data accessible through the affected connectors. The CVSS v3.1 score is 4.8, reflecting a high confidentiality impact.


Authoritative CVE Metadata - CVSS Base Score: 4.8 (MEDIUM) - Published: 2025-04-15T21:16:00.970 - Last Modified: 2026-09-03T18:52:36.070

Original Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N).

"The beginning of knowledge is the discovery of something we do not understand."

— Frank Herbert
Source: NVD