CVE-2019-25680
HIGHAdvance Gift Shop Pro Script 2.0.3 SQL Injection via search
Title source: cnaDescription
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.
Exploits (1)
References (3)
Core 3
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Advance Gift Shop Pro Script 2.0.3 SQL Injection via search
https://www.vulncheck.com/advisories/advance-gift-shop-pro-script-sql-injection-via-search
Scores
CVSS v3
8.2
EPSS
0.0011
EPSS Percentile
28.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (1)
Phpscriptsmall/Advance Gift Shop Pro Script
2.0.3
Published
Apr 05, 2026
Tracked Since
Apr 06, 2026