CVE-2025-1870: SQL injection vulnerability in 101news
Published Mar 3, 2025
·Updated
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.
Affected Software
2 affected components
101news 101news>=1.0
Mayurik Best Online News Portal=1.0
Event History
Mar 3, 2025
CVE Published
via MITRE·12:50 PM
Data Sourced
via MITRE·12:50 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1870?
CVE-2025-1870 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2025-1870?
To fix CVE-2025-1870, sanitize and validate all user inputs, particularly the 'pagedescription' parameter in admin/aboutus.php.
3
What software is affected by CVE-2025-1870?
CVE-2025-1870 affects version 1.0 of the 101news software.
4
What type of vulnerability is CVE-2025-1870?
CVE-2025-1870 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL code.
5
Where can I find more information on CVE-2025-1870?
Additional information on CVE-2025-1870 can be found in security advisories such as those from MITRE.