CVE-2025-5632: code-projects/anirbandutta9 Content Management System/News-Buzz users.php sql injection
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argument changetoadmin leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5632?
CVE-2025-5632 has been declared as critical.
How do I fix CVE-2025-5632?
To address CVE-2025-5632, it is recommended to update the News-Buzz Content Management System to the latest version that resolves this vulnerability.
What components are affected by CVE-2025-5632?
CVE-2025-5632 affects the file /admin/users.php in News-Buzz version 1.0.
What kind of attack does CVE-2025-5632 allow?
CVE-2025-5632 allows for unauthorized elevation of privileges through manipulation of the argument change_to_admin.
Who is affected by CVE-2025-5632?
Anyone using the News-Buzz 1.0 Content Management System is potentially affected by CVE-2025-5632.