Unauthorized Database Access in CF Image Hosting Script by CodeFuture
CVE-2019-25709
Key Information:
- Vendor
Davidtavarez
- Status
- Vendor
- CVE Published:
- 12 April 2026
Badges
What is CVE-2019-25709?
CF Image Hosting Script version 1.6.5 exposes a critical vulnerability that allows unauthorized users to access the application database. By exploiting this flaw, attackers can download the imgdb.db file located in the upload/data directory, obtaining sensitive information such as plaintext delete IDs. These IDs can then be exploited to remove images from the database using the d parameter, leading to potential data loss and unauthorized manipulation of user content.
Affected Version(s)
CF Image Hosting Script 1.6.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
