First published: Mon Mar 03 2025(Updated: )
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
101news | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1871 is classified as a high-severity SQL injection vulnerability.
To fix CVE-2025-1871, update to a patched version of 101news that addresses the SQL injection flaw.
CVE-2025-1871 affects 101news version 1.0 and earlier.
CVE-2025-1871 can allow attackers to execute arbitrary SQL commands, potentially leading to data leakage or loss.
More information about CVE-2025-1871 can be found in security advisories and vulnerability databases.