SQL Injection Vulnerability in Redaxo CMS Addon by Wende60
CVE-2018-25319
Key Information:
- Vendor
Wende60
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2018-25319?
The Redaxo CMS Addon MyEvents version 2.2.1 is susceptible to an SQL injection vulnerability, enabling authenticated attackers to craft malicious SQL queries through the myevents_id parameter. By sending specially constructed GET requests to the event_add.php page, attackers can manipulate the underlying database, potentially leading to unauthorized access or modification of sensitive information. This vulnerability underscores the importance of input validation and secure coding practices to protect against database manipulation attacks.
Affected Version(s)
Redaxo CMS Addon MyEvents 2.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
