SQL Injection Vulnerability in 101news by INCIBE
CVE-2025-1869

9.3CRITICAL

Key Information:

Vendor

Mayuri K

Status
Vendor
CVE Published:
3 March 2025

What is CVE-2025-1869?

A critical SQL injection vulnerability has been identified in 101news, specifically impacting versions 1.0. This security flaw arises through the 'username' parameter in the admin/check_availability.php file, potentially allowing unauthorized access and manipulation of the database. It is essential for users of 101news to implement immediate security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

101news 1.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.