PT-2026-26926 · Unknown · Phptransformer
Ihsan Sencan
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2019-25578
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phpTransformer version 2016.9
Description
The software contains an SQL injection issue that could allow remote attackers to execute arbitrary SQL queries. This is achieved by injecting malicious code through the
idnews parameter. Attackers can send crafted GET requests to the ''GeneratePDF.php'' endpoint with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.Recommendations
Apply updates to address the issue in phpTransformer version 2016.9. As a temporary workaround, restrict access to the ''GeneratePDF.php'' endpoint. Avoid using the
idnews parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phptransformer