CVE-2019-25439

HIGH

NoviSmart CMS - SQL Injection

Title source: llm
STIX 2.1

Description

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

Exploits (1)

exploitdb WORKING POC
by n1x_ · textwebappsphp
https://www.exploit-db.com/exploits/47152

Scores

CVSS v3 8.2
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Novismart/NoviSmart CMS
Published Feb 22, 2026
Tracked Since Feb 22, 2026