CRITICAL🇵🇱 Wersja polska

CVE-2025-1872

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient validation and sanitization of input data passed through the 'sadminusername' parameter in the admin/add-subadmins.php endpoint. An attacker can inject malicious SQL code directly into the query executed on the database server side. Due to the lack of authentication requirement (PR:N, UI:N), the exploit can be performed remotely over the network without any user interaction.

Impact

An attacker can obtain unauthorized read, modification, or deletion of data in the application database, including administrator and sub-administrator credentials. Depending on the database server configuration, it is also possible to gain full control over the service data.

Mitigation & patch

Patches available from the vendor should be applied according to the references. It is also recommended to implement parameterized queries (prepared statements) and restrict access to the administrative panel exclusively to trusted IP addresses.

Who is affected

101news application (Mayurik Best Online News Portal) version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1871CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametry category i subcategory

CVE-2025-1873CRITICAL9.3PL ✓same product

SQL Injection w 101news przez parametry pagetitle i pagedescription

CVE-2025-1870CRITICAL9.3PL ✓same product

SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription

CVE-2025-1869CRITICAL9.3PL ✓same product

SQL Injection w 101news — podatność w parametrze 'username'

CVE-2025-1874CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametr 'description' w panelu admina