PT-2026-27373 · Matri4Web · Matrimony Website Script

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2019-25639

CVSS v3.1

8.2

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various POST parameters. Attackers can inject malicious SQL payloads into parameters like txtGender, religion, Fage, and cboCountry across simplesearch results.php, advsearch results.php, specialcase results.php, locational results.php, and registration2.php to extract sensitive database information or execute arbitrary SQL commands.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25639

Affected Products

Matrimony Website Script