PT-2026-21309 · Unknown · Blue Smiley Organizer

Cakes

·

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2019-25431

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions delpino73 Blue-Smiley-Organizer version 1.32
Description The software contains an SQL injection issue in the datetime parameter. Unauthenticated attackers can manipulate database queries by injecting SQL code through POST requests. This allows attackers to extract sensitive data using boolean-based blind and time-based blind techniques, or write files to the server using INTO OUTFILE statements.
Recommendations Apply a fix for version 1.32 to address the SQL injection issue in the datetime parameter.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25431

Affected Products

Blue Smiley Organizer