CRITICAL🇵🇱 Wersja polska

CVE-2025-1873

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.

🤖 AI Analysis
How it works

The vulnerability occurs in the 'pagetitle' and 'pagedescription' parameters handled by the admin/contactus.php script. User-supplied data is not properly validated or sanitized before being used in SQL queries (CWE-89). An attacker can inject malicious SQL code fragments over the network without needing special privileges or victim interaction, thereby gaining unauthorized access to the database.

Impact

An attacker can gain full access to the application's database, steal, modify, or delete stored data. Depending on server configuration, it is also possible to take control of the database system.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additionally, it is recommended to implement parameterized SQL queries or ORM mechanisms to eliminate the SQL injection vulnerability class, as well as restrict access to the admin panel exclusively to trusted IP addresses.

Who is affected

101news application (Mayurik Best Online News Portal) version 1.0 — admin/contactus.php file (parameters 'pagetitle' and 'pagedescription').

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1871CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametry category i subcategory

CVE-2025-1872CRITICAL9.3PL ✓same product

SQL Injection w 101news — parametr sadminusername w panelu admina

CVE-2025-1870CRITICAL9.3PL ✓same product

SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription

CVE-2025-1869CRITICAL9.3PL ✓same product

SQL Injection w 101news — podatność w parametrze 'username'

CVE-2025-1874CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametr 'description' w panelu admina