CRITICAL🇵🇱 Wersja polska

CVE-2025-1869

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.

🤖 AI Analysis
How it works

An attacker sends a crafted HTTP request to the admin/check_avalability.php endpoint, injecting malicious SQL code through the 'username' parameter. Data passed by the user is not properly validated or parameterized before use in a database query. This allows manipulation of the logic of SQL queries executed on the server side.

Impact

An attacker can gain unauthorized access to data stored in the database, including user and administrator credentials, and potentially modify or delete service data. The vulnerability requires no authentication or victim interaction, which significantly increases its criticality.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Additionally, it is recommended to use parameterized SQL queries (prepared statements) and server-side input validation as remedial measures in the application layer.

Who is affected

101news application (Mayurik Best Online News Portal) version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1872CRITICAL9.3PL ✓same product

SQL Injection w 101news — parametr sadminusername w panelu admina

CVE-2025-1873CRITICAL9.3PL ✓same product

SQL Injection w 101news przez parametry pagetitle i pagedescription

CVE-2025-1871CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametry category i subcategory

CVE-2025-1870CRITICAL9.3PL ✓same product

SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription

CVE-2025-1874CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametr 'description' w panelu admina