PT-2025-53687 · Unknown · Biggidroid Simple Php Cms

Dazhi

+1

·

Published

2025-12-29

·

Updated

2025-12-29

·

CVE-2025-15169

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BiggiDroid Simple PHP CMS version 1.0
Description A weakness exists in BiggiDroid Simple PHP CMS 1.0. The issue is related to some unknown functionality within the /admin/editsite.php file. Manipulation of the ID parameter can lead to SQL injection. The attack can be performed remotely. An exploit for this issue has been publicly released. The vendor was contacted regarding this disclosure but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15169

Affected Products

Biggidroid Simple Php Cms