PT-2026-46198 · Care2X · Care2X

Carlos Avila

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25728

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck config cookie parameter. Attackers can inject malicious SQL through the ck config cookie in multiple endpoints including login.php, indexframe.php, and various module files to extract sensitive database information without authentication.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25728

Affected Products

Care2X