PT-2026-24998 · Sourceforge+1 · 202Cms
Published
2026-03-12
·
Updated
2026-03-16
·
CVE-2019-25538
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
202CMS version 10 beta
Description
An SQL injection issue exists that allows unauthenticated attackers to manipulate database queries. This is achieved by injecting SQL code through the
log user parameter. Attackers can send crafted requests with malicious SQL statements in the log user field to extract sensitive database information or modify database contents. The API endpoint involved is not specified.Recommendations
Apply a fix for 202CMS version 10 beta to address the SQL injection issue in the
log user parameter.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
202Cms