Critical severity9.8NVD Advisory· Published Apr 12, 2026· Updated Apr 23, 2026
CVE-2019-25709
CVE-2019-25709
Description
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
Affected products
1- cpe:2.3:a:codefuture:image_hosting_script:1.6.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46094nvdExploitVDB Entry
- davidtavarez.github.ionvdThird Party Advisory
- www.vulncheck.com/advisories/cf-image-hosting-script-unauthorized-database-accessnvdThird Party Advisory
- forum.codefuture.co.uk/showthread.phpnvdBroken Link
News mentions
0No linked articles in our index yet.