Official Product Homepageproduct
http://www.impresscms.org/ CVE-2019-25703
HIGH
ImpressCMS 1.3.11 SQL Injection via bid Parameter
Record summary
CVE-2019-25703 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ImpressCMSBrowse Impresscms / ImpressCMS | CVE List | 1.3.11 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBImpressCMS 1.3.11 - 'bid' SQL InjectionExploitDB exploitby Mehmet OnderNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25703 Product Referenceproduct
https://sourceforge.net/projects/impresscms/files/v1.3.11/impresscms_1.3.11.zip ExploitDB-46239exploit
https://www.exploit-db.com/exploits/46239 VulnCheck Advisory: ImpressCMS 1.3.11 SQL Injection via bid ParameterThird-party advisory
https://www.vulncheck.com/advisories/impresscms-sql-injection-via-bid-parameter