CRITICAL🇵🇱 Wersja polska

CVE-2025-1874

CVSS 9.3v4.0pub. 2025-03-03upd. 2025-03-07

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.

🤖 AI Analysis
How it works

The attacker sends specially crafted input data through the 'description' parameter in the category addition form (admin/add-category.php). The application does not filter or parametrize the passed values, allowing arbitrary SQL commands to be injected directly into the query executed on the database server. The attack can be performed remotely, without authentication, and without any interaction on the victim's side.

Impact

An attacker can gain unauthorized access to data stored in the database, including authentication credentials, website content, and user data. Depending on server configuration, it is also possible to modify or delete data, and potentially execute system commands.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. It is also recommended to implement parameterized SQL queries (prepared statements) and validation and sanitization of input data on the server side. Until the patch is applied, consider restricting access to the admin panel only to trusted IP addresses.

Who is affected

101news application (Mayurik Best Online News Portal) version 1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mayurik Best Online News Portal

    APP
    Mayurik
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-1871CRITICAL9.3PL ✓same product

SQL Injection w 101news – parametry category i subcategory

CVE-2025-1872CRITICAL9.3PL ✓same product

SQL Injection w 101news — parametr sadminusername w panelu admina

CVE-2025-1870CRITICAL9.3PL ✓same product

SQL Injection w 101news (Mayurik Best Online News Portal) via parametr pagedescription

CVE-2025-1869CRITICAL9.3PL ✓same product

SQL Injection w 101news — podatność w parametrze 'username'

CVE-2025-1873CRITICAL9.3PL ✓same product

SQL Injection w 101news przez parametry pagetitle i pagedescription