CVE-2025-1874: SQL injection vulnerability in 101news
Published Mar 3, 2025
·Updated
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
Affected Software
2 affected components
101news 101news<=1.0
Mayurik Best Online News Portal=1.0
Event History
Mar 3, 2025
CVE Published
via MITRE·12:52 PM
Data Sourced
via MITRE·12:52 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1874?
CVE-2025-1874 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-1874?
To fix CVE-2025-1874, validate and sanitize the input for the "description" parameter in admin/add-category.php to prevent SQL injection.
3
Which versions of 101news are affected by CVE-2025-1874?
CVE-2025-1874 affects 101news version 1.0 and earlier.
4
What kind of attack can be executed using CVE-2025-1874?
CVE-2025-1874 allows attackers to execute unauthorized SQL commands which could lead to data exposure or manipulation.
5
Is there a patch available for CVE-2025-1874?
As of now, there is no official patch announced for CVE-2025-1874.