CVE-2019-25573

Source
https://cve.org/CVERecord?id=CVE-2019-25573
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25573.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-25573
Published
2026-03-21T16:16:00.753Z
Modified
2026-07-08T16:08:12.068139Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

References

Affected packages

Git / github.com/greencms/greencms

Affected ranges

Type
GIT
Repo
https://github.com/greencms/greencms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:njtech:greencms:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.1.0612"
        },
        {
            "last_affected": "2.3.0603"
        }
    ]
}

Affected versions

v2.*
v2.3.0101
v2.3.0215
v2.3.0603

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25573.json"