High severity8.2NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026
CVE-2019-25489
CVE-2019-25489
Description
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sensitive database information or cause denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:doditsolutions:airbnb_clone_script:4:*:*:*:*:*:*:*
- Range: V4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.