CVE-2025-1873: SQL injection vulnerability in 101news
Published Mar 3, 2025
·Updated
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.
Affected Software
2 affected components
101news 101news<=1.0
Mayurik Best Online News Portal=1.0
Event History
Mar 3, 2025
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1873?
CVE-2025-1873 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-1873?
To fix CVE-2025-1873, update to the latest version of 101news that addresses this vulnerability.
3
What are the affected parameters in CVE-2025-1873?
The affected parameters in CVE-2025-1873 are "pagetitle" and "pagedescription" in admin/contactus.php.
4
What versions of 101news are impacted by CVE-2025-1873?
CVE-2025-1873 impacts 101news version 1.0 and below.
5
Is CVE-2025-1873 remotely exploitable?
Yes, CVE-2025-1873 is remotely exploitable due to the nature of the SQL injection vulnerability.