LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2019-25457

CVE-2019-25457 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: February 23, 2026

Web Ofisi Firma - SQL Injection

Published: February 22, 2026Updated: February 23, 2026Remote Exploitable

Overview

Web Ofisi Firma v13 contains an sql injection caused by unsanitized 'oz' array parameter in category pages, letting unauthenticated attackers extract sensitive database information via time-based blind SQL injection.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can extract sensitive database information, potentially compromising the entire database.

Mitigation

Update to the latest version.

Details

CVE ID
CVE-2019-25457
Severity
High
CVSS Score
8.2
Type
sql_injection
Status
unconfirmed

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N