PT-2026-26926 · Unknown · Phptransformer

Ihsan Sencan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2019-25578

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpTransformer version 2016.9
Description The software contains an SQL injection issue that could allow remote attackers to execute arbitrary SQL queries. This is achieved by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to the ''GeneratePDF.php'' endpoint with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.
Recommendations Apply updates to address the issue in phpTransformer version 2016.9. As a temporary workaround, restrict access to the ''GeneratePDF.php'' endpoint. Avoid using the idnews parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2019-25578

Affected Products

Phptransformer