CVE-2025-1873
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 89
Summary
CVE-2025-1873 signifies a newly discovered SQL injection vulnerability. Affecting the 1.0 version of 101news, this issue can be exploited via the "pagetitle" and "pagedescription" parameters in the "admin/contactus.php" file. An attacker can inject malicious SQL commands, potentially taking control of databases or accessing sensitive information. This vulnerability poses a significant risk to websites using the 101news platform and requires immediate remediation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.