CVE-2025-1875
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 89
Summary
CVE-2025-1875 is a newly discovered SQL injection vulnerability that affects the 1.0 version of 101news. The vulnerability is located in the "searchtitle" parameter of the "search.php" file. An attacker can exploit this weakness by injecting malicious SQL queries, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. Users are strongly advised to update to a patched version of 101news to mitigate this risk. SQL injection attacks can lead to serious data breaches and system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.