CVE-2019-25457 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: February 23, 2026
Web Ofisi Firma - SQL Injection
Published: February 22, 2026Updated: February 23, 2026Remote Exploitable
Overview
Web Ofisi Firma v13 contains an sql injection caused by unsanitized 'oz' array parameter in category pages, letting unauthenticated attackers extract sensitive database information via time-based blind SQL injection.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Unauthenticated attackers can extract sensitive database information, potentially compromising the entire database.
Mitigation
Update to the latest version.
References
Related Resources
Details
- CVE ID
- CVE-2019-25457
- Severity
- High
- CVSS Score
- 8.2
- Type
- sql_injection
- Status
- unconfirmed
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N