CVE-2025-1874

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mayurik:best_online_news_portal:1.0:*:*:*:*:*:*:*

History

07 Mar 2025, 14:45

Type Values Removed Values Added
CPE cpe:2.3:a:mayurik:best_online_news_portal:1.0:*:*:*:*:*:*:*
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-101news - Third Party Advisory
Summary
  • (es) Se ha encontrado una vulnerabilidad de inyección SQL en 101news que afecta a la versión 1.0 a través del parámetro "descripción" en admin/add-category.php.
First Time Mayurik
Mayurik best Online News Portal
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

03 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 13:15

Updated : 2025-03-07 14:45


NVD link : CVE-2025-1874

Mitre link : CVE-2025-1874

CVE.ORG link : CVE-2025-1874


JSON object : View

Products Affected

mayurik

  • best_online_news_portal
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')