PT-2026-24974 · Jettweb · Hazir Haber Sitesi Scripti+1

Published

2026-03-12

·

Updated

2026-03-12

·

CVE-2019-25514

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jettweb PHP Hazir Haber Sitesi Scripti version 3
Description The software contains an SQL injection issue that allows attackers to inject malicious SQL commands. This is possible through manipulation of the kelime parameter in POST requests. Attackers can use UNION-based SQL injection payloads to extract sensitive data from the database or bypass authentication controls.
Recommendations Versions prior to version 3 are recommended.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25514

Affected Products

Hazir Haber Sitesi Scripti
Php Stock News Site Script