CVE-2025-1869

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:best_online_news_portal:1.0:*:*:*:*:*:*:*

History

07 Mar 2025, 14:45

Type Values Removed Values Added
First Time Mayurik best Online News Portal
Mayurik
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Se ha encontrado una vulnerabilidad de inyección SQL en 101news que afecta a la versión 1.0 a través del parámetro "nombre de usuario" en admin/check_avalability.php.
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news - Third Party Advisory
CPE cpe:2.3:a:mayurik:best_online_news_portal:1.0:*:*:*:*:*:*:*

03 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 13:15

Updated : 2025-03-07 14:45


NVD link : CVE-2025-1869

Mitre link : CVE-2025-1869

CVE.ORG link : CVE-2025-1869


JSON object : View

Products Affected

mayurik

  • best_online_news_portal
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')