Vulnerability Description
delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through POST requests to extract sensitive data using boolean-based blind and time-based blind techniques, or write files to the server using INTO OUTFILE statements.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/delpino73/Blue-Smiley-Organizer
- https://www.exploit-db.com/exploits/47550
- https://www.vulncheck.com/advisories/delpino-blue-smiley-organizer-sql-injection
FAQ
What is CVE-2019-25431?
CVE-2019-25431 is a vulnerability with a CVSS score of 8.2 (HIGH). delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL co...
How severe is CVE-2019-25431?
CVE-2019-25431 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25431?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.