CVE-2019-25703

HIGH

ImpressCMS 1.3.11 SQL Injection via bid Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25703. PoCs published by Mehmet Onder.

AI-analyzed exploit summary The exploit demonstrates a time-based blind SQL injection vulnerability in ImpressCMS 1.3.11 via the 'bid' POST parameter. The payload uses SLEEP(5) to confirm the vulnerability, indicating successful exploitation.

Description

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.

Exploits (1)

exploitdb WORKING POC
by Mehmet Onder · textwebappsphp
https://www.exploit-db.com/exploits/46239

The exploit demonstrates a time-based blind SQL injection vulnerability in ImpressCMS 1.3.11 via the 'bid' POST parameter. The payload uses SLEEP(5) to confirm the vulnerability, indicating successful exploitation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: ImpressCMS v1.3.11
Auth required
Prerequisites: access to the admin.php endpoint · valid session or authentication
devstral-2 · analyzed Apr 12, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46239
https://www.exploit-db.com/exploits/46239
Product product
Official Product Homepage
http://www.impresscms.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: ImpressCMS 1.3.11 SQL Injection via bid Parameter
https://www.vulncheck.com/advisories/impresscms-sql-injection-via-bid-parameter

Scores

CVSS v3 7.1
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (2)
impresscms/impresscms 1.3.11
Impresscms/ImpressCMS 1.3.11
Published Apr 12, 2026
Tracked Since Apr 12, 2026