nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25446 CVE-2019-25446
HIGH
DIGIT CENTRIS ERP Every version SQL Injection via datum1 Parameter
Record summary
CVE-2019-25446 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameters to extract or modify sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DIGIT CENTRISBrowse Digit-Rs / DIGIT CENTRIS | CVE List | * | affected |
Proofs of concept
1Catalogued exploits
ExploitDBDIGIT CENTRIS 4 ERP - 'datum1' SQL InjectionExploitDB exploitby n1x_Not analyzed1 file
References
3ExploitDB-47401exploit
https://www.exploit-db.com/exploits/47401 VulnCheck Advisory: DIGIT CENTRIS ERP Every version SQL Injection via datum1 ParameterThird-party advisory
https://www.vulncheck.com/advisories/digit-centris-erp-every-version-sql-injection-via-datum-parameter