PT-2025-54211 · Unknown · Biggidroid Simple Php Cms

Devil_Run_Sun

·

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2025-15263

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BiggiDroid Simple PHP CMS version 1.0
Description A flaw exists in BiggiDroid Simple PHP CMS 1.0, specifically within the Admin Login component. Manipulation of the Username argument in the /admin/login.php file can lead to SQL injection. This attack can be carried out remotely. The exploit for this issue has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15263

Affected Products

Biggidroid Simple Php Cms