← Zurück zur CVE-Suche

CVE-2019-25668

News Website Script

Beschreibung

News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.

CVSS 8.2EPSS 0.4%Risiko 0.85
Quelle öffnen
Veröffentlicht
2026-04-05 21:16:44
Betroffene Versionen
<=2.0.5
Typ
Package
Zuletzt geändert
2026-07-24 22:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N