CVE-2019-25635

Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the profile_list endpoint. Attackers can inject SQL code via the up_cast, s_mother, and s_religion parameters to extract sensitive database information using time-based or error-based techniques.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zeeways:matrimony_cms:-:*:*:*:*:*:*:*

History

15 Apr 2026, 15:31

Type Values Removed Values Added
First Time Zeeways
Zeeways matrimony Cms
CPE cpe:2.3:a:zeeways:matrimony_cms:-:*:*:*:*:*:*:*
Summary
  • (es) Zeeways Matrimony CMS contiene múltiples vulnerabilidades de inyección SQL que permiten a atacantes no autenticados manipular consultas a la base de datos a través del endpoint profile_list. Los atacantes pueden inyectar código SQL a través de los parámetros up_cast, s_mother y s_religion para extraer información sensible de la base de datos utilizando técnicas basadas en tiempo o basadas en errores.
References () http://www.zeeways.com/matrimony-cms/4/productdetail - () http://www.zeeways.com/matrimony-cms/4/productdetail - Broken Link
References () https://www.exploit-db.com/exploits/46603 - () https://www.exploit-db.com/exploits/46603 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/zeeways-matrimony-cms-lastest-sql-injection-via-profile-list - () https://www.vulncheck.com/advisories/zeeways-matrimony-cms-lastest-sql-injection-via-profile-list - Third Party Advisory

24 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 12:16

Updated : 2026-04-15 15:31


NVD link : CVE-2019-25635

Mitre link : CVE-2019-25635

CVE.ORG link : CVE-2019-25635


JSON object : View

Products Affected

zeeways

  • matrimony_cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')