SQL Injection Vulnerability in Meeplace Business Review Script
CVE-2019-25638
What is CVE-2019-25638?
The Meeplace Business Review Script is vulnerable to SQL injection through the 'id' parameter in the addclick.php endpoint. This security flaw allows attackers, without authentication, to craft GET requests that exploit the SQL logic processing, potentially enabling them to execute arbitrary SQL queries. By injecting malicious code into the 'id' parameter, an attacker can extract sensitive information from the database or disrupt service functionality, posing a significant threat to user data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Meeplace Business Review Script *
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
