Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-25713

MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blind, or stacked query payloads to extract sensitive database information or manipulate data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 7.0%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2019-25713
  • Myt Project » Myt » Version: 1.5.1
    cpe:2.3:a:myt_project:myt:1.5.1


Contact Us

Shodan ® - All rights reserved