CVE-2019-25538

Publication date

2026-03-12 15:37:09

Family

VulnCheck

State

PUBLISHED

Description

202CMS v10 beta contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send crafted requests with malicious SQL statements in the log_user field to extract sensitive database information or modify database contents.