CVE-2019-25699
HIGHNewsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
Title source: cnaDescription
Newsbull Haber Script 1.0.0 contains multiple SQL injection vulnerabilities in the search parameter that allow authenticated attackers to extract database information through time-based, blind, and boolean-based injection techniques. Attackers can inject malicious SQL code through the search parameter in endpoints like /admin/comment/records, /admin/category/records, /admin/news/records, and /admin/menu/childs to manipulate database queries and retrieve sensitive data.
Exploits (1)
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
https://www.vulncheck.com/advisories/newsbull-haber-script-authenticated-sql-injection-via-search-parameter
Scores
CVSS v3
7.1
EPSS
0.0001
EPSS Percentile
1.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (2)
gurkanuzunca/newsbull
1.0.0
Newsbull/Newsbull Haber Script
1.0.0
Published
Apr 12, 2026
Tracked Since
Apr 12, 2026