CVE-2019-25446

HIGH

DIGIT CENTRIS ERP - SQL Injection

Title source: llm
STIX 2.1

Description

DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters. Attackers can send POST requests to /korisnikinfo.php with malicious SQL syntax in these parameters to extract or modify sensitive database information.

Exploits (1)

exploitdb WORKING POC
by n1x_ · textwebappsphp
https://www.exploit-db.com/exploits/47401

Scores

CVSS v3 8.2
EPSS 0.0012
EPSS Percentile 30.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Digit-Rs/DIGIT CENTRIS
Published Feb 22, 2026
Tracked Since Feb 22, 2026