nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25506 CVE-2019-25506
HIGH
FreeSMS 2.1.2 Authentication Bypass via SQL Injection
Record summary
CVE-2019-25506 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login endpoint. Attackers can exploit the vulnerable password parameter in requests to /pages/crc_handler.php?method=login to authenticate as any known user and subsequently modify their password via the profile update function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FreeSMSBrowse Freesms / FreeSMS | CVE List | 2.1.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFreeSMS 2.1.2 - SQL Injection (Authentication Bypass)ExploitDB exploitby Yilmaz DegirmenciNot analyzed1 file
References
3ExploitDB-46658exploit
https://www.exploit-db.com/exploits/46658 VulnCheck Advisory: FreeSMS 2.1.2 Authentication Bypass via SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/freesms-authentication-bypass-via-sql-injection