Security Advisory

CVE-2019-25703

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-12 12:28:50
Last updated 2026-04-13 12:08:59
Assigner VulnCheck
State PUBLISHED

Description

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the bid parameter. Attackers can send POST requests to the admin.php endpoint with malicious bid values containing SQL commands to extract sensitive database information.