xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.
History

Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Xbtitfm
Xbtitfm xbtitfm
Vendors & Products Xbtitfm
Xbtitfm xbtitfm

Thu, 11 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.
Title xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-11T21:42:23.320Z

Updated: 2025-12-11T21:42:23.320Z

Reserved: 2025-12-11T11:49:20.719Z

Link: CVE-2024-58309

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-11T22:15:52.487

Modified: 2025-12-11T22:15:52.487

Link: CVE-2024-58309

cve-icon Redhat

No data.