SQL Injection Vulnerability in News-Buzz by Code Projects
CVE-2025-5631
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 5 June 2025
Badges
What is CVE-2025-5631?
A security vulnerability has been identified in the News-Buzz content management system, specifically in the publicposts.php file. This issue arises from inadequate validation and handling of user-supplied input, allowing attackers to manipulate the 'post' argument. By exploiting this vulnerability, an attacker can execute arbitrary SQL queries against the database, potentially leading to unauthorized data access, data corruption, or further exploitation of the hosting environment. Remediation is crucial as the exploit has been publicly disclosed, and attackers may leverage it in the wild.
Affected Version(s)
Content Management System 1.0
Content Management System 1.0
News-Buzz 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved