Official Product Homepageproduct
https://aiovideodl.ml/ CVE-2019-25726
HIGH
All in One Video Downloader 1.2 SQL Injection via admin page-edit
Record summary
CVE-2019-25726 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames, databases, and version details.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
All in One Video DownloaderBrowse Nicheoffice / All in One Video Downloader | CVE List | 1.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAll in One Video Downloader 1.2 - (Authenticated) SQL InjectionExploitDB exploitby Deyaa MuhammadNot analyzed1 file
References
6Product Referenceproduct
https://codecanyon.net/item/all-in-one-video-downloader-youtube-and-more/22599418 Official Product Homepageproduct
https://nicheoffice.web.tr/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25726 ExploitDB-46077exploit
https://www.exploit-db.com/exploits/46077 VulnCheck Advisory: All in One Video Downloader 1.2 SQL Injection via admin page-editThird-party advisory
https://www.vulncheck.com/advisories/all-in-one-video-downloader-sql-injection-via-admin-page-edit