HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2019-25697 — CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated ...

·Source: NIST NVD

Updated:

Executive Summary

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and credentials.

Analysis

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to category.php with malicious cat_id values to extract sensitive database information including usernames and credentials. CVSS Score: 8.2. Published: 2026-04-12T13:16:32.603.

Indicators of Compromise (1)

CVE (1)
CVE-2019-25697
Source Attribution

Originally published by NIST NVD on Apr 12, 2026. Verified by: NIST.

Related Threats