Official Product Homepageproduct
http://www2.xataboost.com/ CVE-2018-25300
HIGH
XATABoost CMS 1.0.0 SQL Injection via news.php
Record summary
CVE-2018-25300 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
XATABoost CMSBrowse xataboost / XATABoost CMS | CVE List | 1.0.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBXATABoost 1.0.0 - SQL InjectionExploitDB exploitby MgThuraMoeMyintNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25300 ExploitDB-44622exploit
https://www.exploit-db.com/exploits/44622 VulnCheck Advisory: XATABoost CMS 1.0.0 SQL Injection via news.phpThird-party advisory
https://www.vulncheck.com/advisories/xataboost-cms-sql-injection-via-news-php