CRITICAL🇵🇱 Wersja polska

CVE-2025-1871

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.

🤖 AI Analysis
How it works

The vulnerability results from the lack of proper validation and sanitization of input data passed in the 'category' and 'subcategory' parameters in requests to the admin/add-subcategory.php file. An attacker can inject malicious SQL code directly into the query executed on the database. Due to network accessibility without requiring authentication, the exploit can be performed remotely by any user.

Impact

An attacker can gain unauthorized access to data stored in the database, modify or delete data, and in favorable circumstances take control of the application or database server.

Mitigation & patch

Apply patches available from the vendor according to the references. As immediate remedial measures, it is recommended to restrict network access to the administration panel (admin/) and implement validation and parameterization of SQL queries on the application side.

Who is affected

Mayurik Best Online News Portal (101news) version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1872CRITICAL9.3PL ✓same product

SQL Injection w 101news — parametr sadminusername w panelu admina

CVE-2025-1873CRITICAL9.3PL ✓same product

SQL Injection w 101news przez parametry pagetitle i pagedescription

CVE-2025-1870CRITICAL9.3PL ✓same product

SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription

CVE-2025-1869CRITICAL9.3PL ✓same product

SQL Injection w 101news — podatność w parametrze 'username'

CVE-2025-1874CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametr 'description' w panelu admina