Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database credentials, usernames, and version information.
History

Thu, 04 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database credentials, usernames, and version information.
Title Listing Hub CMS 1.0 SQL Injection via pages.php id
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-04T13:22:37.291Z

Reserved: 2026-06-04T10:54:35.580Z

Link: CVE-2019-25730

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T14:16:30.830

Modified: 2026-06-04T14:16:30.830

Link: CVE-2019-25730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.