ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.
References
| Link | Resource |
|---|---|
| http://www.impresscms.org/ | Product |
| https://sourceforge.net/projects/impresscms/files/v1.3.11/impresscms_1.3.11.zip | Product |
| https://www.exploit-db.com/exploits/46239 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/impresscms-sql-injection-via-bid-parameter | Third Party Advisory |
Configurations
History
17 Apr 2026, 16:51
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:impresscms:impresscms:1.3.11:*:*:*:*:*:*:* | |
| First Time |
Impresscms
Impresscms impresscms |
|
| References | () http://www.impresscms.org/ - Product | |
| References | () https://sourceforge.net/projects/impresscms/files/v1.3.11/impresscms_1.3.11.zip - Product | |
| References | () https://www.exploit-db.com/exploits/46239 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/impresscms-sql-injection-via-bid-parameter - Third Party Advisory |
12 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-12 13:16
Updated : 2026-04-17 16:51
NVD link : CVE-2019-25703
Mitre link : CVE-2019-25703
CVE.ORG link : CVE-2019-25703
JSON object : View
Products Affected
impresscms
- impresscms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
