LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2018-25183

CVE-2018-25183 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: March 26, 2026

Shipping System CMS - Authentication Bypass

Published: March 26, 2026Updated: March 26, 2026Remote Exploitable

Overview

Shipping System CMS 1.0 contains an sql injection caused by unsanitized input in the username parameter at the admin login endpoint, letting unauthenticated attackers bypass authentication using boolean-based blind SQL injection.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can bypass authentication, gaining unauthorized access to the system.

Mitigation

Update to the latest version of Shipping System CMS.

Details

CVE ID
CVE-2018-25183
Severity
High
CVSS Score
8.2
Type
sql_injection
Status
new

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N