Record summary

CVE-2019-25529 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using boolean-based blind, time-based blind, or union-based techniques to extract sensitive database information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.4aaffected

Proofs of concept

1

Catalogued exploits

ExploitDBPlaceto CMS Alpha v4 - 'page' SQL InjectionExploitDB exploitby Abdullah ÇelebiNot analyzed1 file
ExploitDB

PoC details

References

5