CVE-2025-1875

SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
INCIBECNA
---
---
CISA-ADPADP
---
---