PT-2026-22961 · Freesms · Freesms

Yilmaz Degirmenci

·

Published

2026-03-04

·

Updated

2026-03-04

·

CVE-2019-25506

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeSMS version 2.1.2
Description The software contains a boolean-based blind SQL injection issue in the password parameter. This allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to the /pages/crc handler.php?method=login endpoint to authenticate as any known user and subsequently modify their password via the profile update function. The vulnerable parameter is password.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /pages/crc handler.php?method=login endpoint. Avoid using the password parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25506

Affected Products

Freesms