CVE-2019-25506 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 4, 2026
FreeSMS - Authentication Bypass
Published: March 4, 2026Updated: March 4, 2026Remote Exploitable
Overview
FreeSMS 2.1.2 contains a boolean-based blind SQL injection caused by unsanitized input in the password parameter at /pages/crc_handler.php?method=login, letting unauthenticated attackers bypass authentication and modify user passwords, exploit requires crafted SQL injection in password parameter.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Unauthenticated attackers can bypass authentication and modify any user's password, leading to full account takeover.
Mitigation
Update to the latest version that patches this SQL injection vulnerability.
References
Related Resources
Details
- CVE ID
- CVE-2019-25506
- Severity
- High
- CVSS Score
- 8.2
- Type
- sql_injection
- Status
- new
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N