CVE-2018-25300
Last modified
CVE-2018-25300 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2018-25300?
How severe is CVE-2018-25300?
How do I fix CVE-2018-25300?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-25294CEWE Photoshow 6.3.4 contains a buffer overflow vulnerabilit…8.7
- CVE-2018-25295ObserverIP Scan Tool 1.4.0.1 contains a denial of service vu…6.9
- CVE-2018-25296P10 Central Management Software 1.4.13 contains a buffer ove…6.8
- CVE-2018-25297Wansview 1.0.2 contains a buffer overflow vulnerability that…6.9
- CVE-2018-25298Merge PACS 7.0 contains a cross-site request forgery vulnera…6.9
- CVE-2018-25299Prime95 29.4b8 contains a local buffer overflow vulnerabilit…8.6
- CVE-2018-25301Easy MPEG to DVD Burner 1.7.11 contains a structured excepti…8.6
- CVE-2018-25302Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a stru…8.5
- CVE-2018-25303Allok Video to DVD Burner 2.6.1217 contains a stack-based bu…8.6
- CVE-2018-25304Free Download Manager 2.0 Build 417 contains a local buffer …8.6
- CVE-2018-25305librsvg2-bin 2.40.13 contains a buffer overflow vulnerabilit…6.9
- CVE-2018-25306PDFunite 0.41.0 contains a buffer overflow vulnerability tha…5.5
Are you affected by CVE-2018-25300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
