CVE-2025-15263
HIGHBiggidroid Simple Php Cms - Injection
Title source: ruleDescription
A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Exploits (1)
References (4)
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
11.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
biggidroid/simple_php_cms
1.0
Published
Dec 30, 2025
Tracked Since
Feb 18, 2026