Unrated severityNVD Advisory· Published Mar 12, 2026· Updated Mar 12, 2026
202CMS v10 beta SQL Injection via log_user Parameter
CVE-2019-25538
Description
202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract sensitive database information or modify database contents.
Affected products
1- Sourceforge/202CMSv5Range: v10 beta
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/46579mitreexploit
- www.vulncheck.com/advisories/202cms-v10-beta-sql-injection-via-log-user-parametermitrethird-party-advisory
- sourceforge.net/projects/b202cms/mitreproduct
News mentions
0No linked articles in our index yet.