nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25662 CVE-2019-25662
HIGH
ResourceSpace 8.6 SQL Injection via watched_searches.php
Record summary
CVE-2019-25662 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ResourceSpaceBrowse Montala / ResourceSpace | CVE List | 8.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBResourceSpace 8.6 - 'watched_searches.php' SQL InjectionExploitDB exploitby dd_Not analyzed1 file
References
5ExploitDB-46308exploit
https://www.exploit-db.com/exploits/46308 Official Product Homepageproduct
https://www.resourcespace.com/ Product Referenceproduct
https://www.resourcespace.com/get VulnCheck Advisory: ResourceSpace 8.6 SQL Injection via watched_searches.phpThird-party advisory
https://www.vulncheck.com/advisories/resourcespace-sql-injection-via-watched-searches-php