High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2019-25539
CVE-2019-25539
Description
202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind injection techniques to extract sensitive database information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Sourceforge/202CMSv5Range: v10 beta
- cpe:2.3:a:konradpl99:202cms:10.0:beta:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/46579nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/202cms-v10-beta-sql-injection-via-register-phpnvdThird Party Advisory
- sourceforge.net/projects/b202cms/nvdProduct
News mentions
0No linked articles in our index yet.