CVE-2019-25642 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 24, 2026
Bootstrapy CMS - SQL Injection
Published: March 24, 2026Updated: March 24, 2026Remote Exploitable
Overview
Bootstrapy CMS contains multiple sql injection vulnerabilities caused by unsanitized POST parameters (thread_id, subject, post-id) in various scripts, letting unauthenticated attackers execute arbitrary SQL queries and extract sensitive data or cause denial of service.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Unauthenticated attackers can execute arbitrary SQL queries, leading to data disclosure or denial of service.
Mitigation
Update Bootstrapy CMS to the latest version with SQL injection fixes.
References
Related Resources
Details
- CVE ID
- CVE-2019-25642
- Severity
- High
- CVSS Score
- 8.2
- Type
- sql_injection
- Status
- new
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N