High severity7.1NVD Advisory· Published Apr 12, 2026· Updated Apr 17, 2026
CVE-2019-25693
CVE-2019-25693
Description
ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive database information including schema names, user credentials, and other confidential data.
Affected products
1- cpe:2.3:a:montala:resourcespace:8.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46274nvdExploitVDB Entry
- www.vulncheck.com/advisories/resourcespace-sql-injection-via-collection-edit-phpnvdThird Party Advisory
- www.resourcespace.comnvdProduct
- www.resourcespace.com/getnvdProduct
News mentions
0No linked articles in our index yet.