XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xataboost
Xataboost xataboost Cms |
|
| Vendors & Products |
Xataboost
Xataboost xataboost Cms |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information. | |
| Title | XATABoost CMS 1.0.0 SQL Injection via news.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-29T19:24:33.836Z
Updated: 2026-04-29T19:24:33.836Z
Reserved: 2026-04-29T12:01:10.933Z
Link: CVE-2018-25300
No data.
Status : Received
Published: 2026-04-29T20:16:25.170
Modified: 2026-04-29T20:16:25.170
Link: CVE-2018-25300
No data.