Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and sensitive database data.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET requests to editgrp.php with malicious gid values using EXTRACTVALUE and CONCAT functions to retrieve schema names and sensitive database data. | |
| Title | Rmedia SMS 1.0 SQL Injection via editgrp.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-06T12:19:04.131Z
Reserved: 2026-03-06T11:32:30.448Z
Link: CVE-2018-25173
No data.
Status : Received
Published: 2026-03-06T13:15:58.820
Modified: 2026-03-06T13:15:58.820
Link: CVE-2018-25173
No data.
OpenCVE Enrichment
No data.