Record summary

CVE-2019-25439 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 23, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List*affected

Proofs of concept

1

Catalogued exploits

ExploitDBNoviSmart CMS - SQL injectionExploitDB exploitby n1x_Not analyzed1 file
ExploitDB

PoC details

References

3