HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2018-25362 — Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows...

·Source: NIST NVD

Updated:

Executive Summary

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials.

Analysis

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials. CVSS Score: 8.2. Published: 2026-05-25T15:16:18.787.

Indicators of Compromise (1)

CVE (1)
CVE-2018-25362
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats