CVE-2019-25439

HIGH

NoviSmart CMS - SQL Injection via Referer HTTP Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25439. PoCs published by n1x_.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NoviSmart CMS via the Referer HTTP header. The payload uses time-based blind SQL injection techniques to confirm the vulnerability.

Description

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

Exploits (1)

exploitdb WORKING POC
by n1x_ · textwebappsphp
https://www.exploit-db.com/exploits/47152

This exploit demonstrates a SQL injection vulnerability in NoviSmart CMS via the Referer HTTP header. The payload uses time-based blind SQL injection techniques to confirm the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: NoviSmart CMS (all versions)
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 22, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47152

Scores

CVSS v3 8.2
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Novismart/NoviSmart CMS
Published Feb 22, 2026
Tracked Since Feb 22, 2026