VYPR

202cms

by Konradpl99

CVEs (2)

  • CVE-2019-25539HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind…

  • CVE-2019-25538HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract…