SQL Injection Vulnerability in Netartmedia PHP Business Directory
CVE-2019-25533
Key Information:
- Vendor
PHPbusinessdirectory
- Vendor
- CVE Published:
- 12 March 2026
Badges
What is CVE-2019-25533?
Netartmedia's PHP Business Directory version 4.2 is susceptible to an SQL injection flaw that can be exploited by unauthenticated users. This vulnerability allows attackers to inject malicious SQL statements through the Email parameter when sending POST requests to the loginaction.php endpoint. Successful exploitation can lead to unauthorized access to sensitive information in the database or bypassing authentication mechanisms. Users of this product should take immediate action to patch the vulnerability to secure their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Netartmedia PHP Business Directory 4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
