PT-2026-21283 · Unknown · Fiverr Clone Script
Mr Winst0N
·
Published
2026-02-20
·
Updated
2026-02-20
·
CVE-2019-25444
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fiverr Clone Script version 1.2.2
Description
The software contains an SQL injection issue that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through the
page parameter to extract sensitive database information or modify database contents. The affected API endpoint is not specified. The vulnerable parameter is page.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the
page parameter.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fiverr Clone Script