CVE-2019-25433: XOOPS CMS 2.5.9 SQL Injection via gerar_pdf.php
XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the gerarpdf.php endpoint with malicious cid values to extract sensitive database information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25433?
The CVE-2019-25433 vulnerability has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2019-25433?
To fix CVE-2019-25433, update XOOPS CMS to the latest version that addresses this SQL injection vulnerability.
What type of attack does CVE-2019-25433 allow?
CVE-2019-25433 allows unauthenticated attackers to perform SQL injection attacks against the gerar_pdf.php endpoint.
What is the affected version for CVE-2019-25433?
CVE-2019-25433 specifically affects XOOPS CMS version 2.5.9.
What is the impact of exploiting CVE-2019-25433?
Exploiting CVE-2019-25433 can result in unauthorized manipulation of database queries, leading to potential data breaches.