CVE-2020-25990

CRITICAL

WebsiteBaker 2.12.2 - SQL Injection via Display Name Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-25990. PoCs published by Roel van Beurden.

AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in WebsiteBaker 2.12.2 via the 'display_name' parameter in /admin/preferences/save.php. It includes a proof-of-concept payload and instructions for using SQLmap to extract database information.

Description

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Exploits (1)

exploitdb WORKING POC
by Roel van Beurden · textwebappsphp
https://www.exploit-db.com/exploits/48849

This exploit demonstrates an authenticated SQL injection vulnerability in WebsiteBaker 2.12.2 via the 'display_name' parameter in /admin/preferences/save.php. It includes a proof-of-concept payload and instructions for using SQLmap to extract database information.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WebsiteBaker 2.12.2
Auth required
Prerequisites: Authenticated access to the WebsiteBaker admin panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://websitebaker.org/pages/en/home.php
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/48849

Scores

CVSS v3 9.8
EPSS 0.0165
EPSS Percentile 73.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
websitebaker/websitebaker 2.12.2
Published Oct 01, 2020
Tracked Since Feb 18, 2026