nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25439 CVE-2019-25439
HIGH
NoviSmart CMS SQL Injection via Referer HTTP Header
Record summary
CVE-2019-25439 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NoviSmart CMSBrowse Novismart / NoviSmart CMS | CVE List | * | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNoviSmart CMS - SQL injectionExploitDB exploitby n1x_Not analyzed1 file
References
3ExploitDB-47152exploit
https://www.exploit-db.com/exploits/47152 VulnCheck Advisory: NoviSmart CMS SQL Injection via Referer HTTP HeaderThird-party advisory
https://www.vulncheck.com/advisories/novismart-cms-sql-injection-via-referer-http-header