CRITICAL🇵🇱 Wersja polska

CVE-2025-1870

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.

🤖 AI Analysis
How it works

The vulnerability results from the lack of proper validation and sanitization of input data passed through the "pagedescription" parameter to the admin/aboutus.php file. An attacker can inject malicious SQL code directly into the query executed by the application against the database. According to the CVSS vector, the attack does not require authentication or any user interaction, and the conditions for its execution are low.

Impact

An attacker can gain unauthorized access to data stored in the database, including sensitive data, and potentially modify or delete data as well as affect the integrity and availability of the application.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Additionally, it is recommended to implement parameterized SQL queries (prepared statements) and restrict network access to the administrative panel (admin/aboutus.php) exclusively to trusted IP addresses.

Who is affected

Mayurik Best Online News Portal (101news) version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1872CRITICAL9.3PL ✓same product

SQL Injection w 101news — parametr sadminusername w panelu admina

CVE-2025-1873CRITICAL9.3PL ✓same product

SQL Injection w 101news przez parametry pagetitle i pagedescription

CVE-2025-1871CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametry category i subcategory

CVE-2025-1869CRITICAL9.3PL ✓same product

SQL Injection w 101news — podatność w parametrze 'username'

CVE-2025-1874CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametr 'description' w panelu admina