SQL Injection Vulnerability in 101news by Incibe
CVE-2025-1870
9.3CRITICAL
What is CVE-2025-1870?
A SQL injection vulnerability exists in 101news, which affects version 1.0. The flaw is triggered through the 'pagedescription' parameter located in admin/aboutus.php, allowing unauthorized access to the database. This could lead to potential data leakage or manipulation, posing a significant risk to the integrity of the application and its data.
Affected Version(s)
101news 1.0