CVE-2025-4728: SourceCodester Best Online News Portal search.php sql injection
A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4728?
CVE-2025-4728 has been classified as a critical vulnerability.
How does CVE-2025-4728 affect the Best Online News Portal?
CVE-2025-4728 affects an unknown function in the file /search.php, allowing SQL injection through the searchtitle argument.
Can CVE-2025-4728 be exploited remotely?
Yes, CVE-2025-4728 can be exploited remotely by an attacker.
How do I fix CVE-2025-4728?
To fix CVE-2025-4728, sanitize user inputs and implement prepared statements to prevent SQL injection.
What versions of the Best Online News Portal are affected by CVE-2025-4728?
CVE-2025-4728 affects all versions of SourceCodester Best Online News Portal.