SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component
References
| Link | Resource |
|---|---|
| https://github.com/chyrp/chyrp | Product |
| https://github.com/chyrp/chyrp/blob/768dd2f7/includes/controller/Admin.php#L1482 | Product |
| https://swetha-subramanian6.github.io/web%20security/cve/chyrp-sqli-cve/ | Exploit Third Party Advisory |
Configurations
History
20 Mar 2026, 13:34
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:chyrp:chyrp:*:*:*:*:*:*:*:* | |
| First Time |
Chyrp
Chyrp chyrp |
|
| References | () https://github.com/chyrp/chyrp - Product | |
| References | () https://github.com/chyrp/chyrp/blob/768dd2f7/includes/controller/Admin.php#L1482 - Product | |
| References | () https://swetha-subramanian6.github.io/web%20security/cve/chyrp-sqli-cve/ - Exploit, Third Party Advisory |
16 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-89 |
16 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 18:16
Updated : 2026-03-20 13:34
NVD link : CVE-2025-69768
Mitre link : CVE-2025-69768
CVE.ORG link : CVE-2025-69768
JSON object : View
Products Affected
chyrp
- chyrp
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
