PT-2026-22961 · Freesms · Freesms
Yilmaz Degirmenci
·
Published
2026-03-04
·
Updated
2026-03-04
·
CVE-2019-25506
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeSMS version 2.1.2
Description
The software contains a boolean-based blind SQL injection issue in the password parameter. This allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to the
/pages/crc handler.php?method=login endpoint to authenticate as any known user and subsequently modify their password via the profile update function. The vulnerable parameter is password.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the
/pages/crc handler.php?method=login endpoint. Avoid using the password parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freesms