High severity7.5NVD Advisory· Published Nov 1, 2021· Updated Jul 9, 2026
CVE-2021-25874
CVE-2021-25874
Description
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:*range: <=10.0
- (no CPE)range: <=10.0
- AVideo/YouPHPTube/AVideo/YouPHPTubedescription
Patches
Vulnerability mechanics
References
2- www.synacktiv.com/sites/default/files/2021-01/YouPHPTube_Multiple_Vulnerabilities.pdfnvdExploitVendor Advisory
- synacktiv.comnvdProduct
News mentions
0No linked articles in our index yet.