CVE-2018-25204

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username field to manipulate database queries and gain unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wecodex:library_cms:1.0:*:*:*:*:*:*:*

History

31 Mar 2026, 01:15

Type Values Removed Values Added
CPE cpe:2.3:a:wecodex:library_cms:1.0:*:*:*:*:*:*:*
First Time Wecodex library Cms
Wecodex
References () https://www.exploit-db.com/exploits/44728 - () https://www.exploit-db.com/exploits/44728 - Exploit, VDB Entry, Third Party Advisory
References () https://www.vulncheck.com/advisories/library-cms-sql-injection-via-admin-login - () https://www.vulncheck.com/advisories/library-cms-sql-injection-via-admin-login - Third Party Advisory
References () https://www.wecodex.com/item/view/library-management-system-in-php-and-mysql/1 - () https://www.wecodex.com/item/view/library-management-system-in-php-and-mysql/1 - Broken Link
Summary
  • (es) Biblioteca CMS 1.0 contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados eludir la autenticación inyectando código SQL a través del parámetro de nombre de usuario. Los atacantes pueden enviar solicitudes POST al endpoint de inicio de sesión de administrador con cargas útiles de inyección SQL ciega basada en booleanos en el campo de nombre de usuario para manipular consultas de base de datos y obtener acceso no autorizado.

26 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 12:16

Updated : 2026-03-31 01:15


NVD link : CVE-2018-25204

Mitre link : CVE-2018-25204

CVE.ORG link : CVE-2018-25204


JSON object : View

Products Affected

wecodex

  • library_cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')