SQL Injection Vulnerability in ASP-CMS by Lou Dong Ji He
CVE-2019-25765
Key Information:
- Vendor
Asp-cms Project
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2019-25765?
ASP-CMS is vulnerable to SQL injection through the commentList.asp endpoint. Malicious actors can manipulate the 'id' parameter in GET requests, allowing them to inject arbitrary SQL code. This vulnerability enables attackers to bypass the application's keyword blocklist by embedding the string 'master' within restricted SQL keywords. This exploitation can lead to the retrieval of sensitive database information, posing a significant security risk for users of ASP-CMS. Recent observations by the Shadowserver Foundation highlight the urgency for swift remediation measures to safeguard against potential data breaches.
Affected Version(s)
ASP-CMS 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
