PT-2025-9318 · 101News · 101News

Rafael Pedrero

·

Published

2025-03-03

·

Updated

2025-03-06

·

CVE-2025-1869

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 101news versions 1.0
Description A SQL injection issue has been identified, specifically through the username parameter in the "admin/check avalability.php" endpoint.
Recommendations For version 1.0, consider restricting access to the "admin/check avalability.php" endpoint until a fix is available, and avoid using the username parameter in this context to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1869

Affected Products

101News