Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25488

Опубликовано: 12 мар. 2026
Источник: nvd
CVSS3: 8.2
CVSS3: 9.8
EPSS Низкий

Описание

Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into the 'tur', 'id', and 'ozellikdil' parameters of the admin/index.php endpoint to extract sensitive database information or cause denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jettweb:php_ready_rent_a_car_site_script:4:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00411
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.2
github
6 месяцев назад

Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into the 'tur', 'id', and 'ozellikdil' parameters of the admin/index.php endpoint to extract sensitive database information or cause denial of service.

EPSS

Процентиль: 34%
0.00411
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-89