PT-2026-30483 · Victoralagwu · Cmssite

·

CVE-2019-25674

·

Published

2026-04-05

·

Updated

2026-04-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMSsite version 1.0
Description An SQL injection flaw allows unauthenticated attackers to manipulate database queries. This is achieved by injecting SQL code via the post parameter when sending GET requests to the 'post.php' endpoint. This can lead to the extraction of sensitive database information or the execution of time-based blind SQL injection attacks, where the attacker determines information by observing the time the server takes to respond to specific queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the post parameter in the 'post.php' endpoint until the issue is resolved.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25674

Affected Products

Cmssite