CVE-2019-25159
low-risk
Published 2024-02-04
A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This affects an unknown part of the file config/cargos.php. The manipulation of the argument dni_profe leads to sql injection. Upgrading to version 4.51.0 is able to address this issue. The identifier of the patch is 678190bee1dfd64b54a2b0e88abfd009e78adce8. It is recommended to upgrade the affected component. The identifier VDB-252717 was assigned to this vulnerability.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
ADJACENT_NETWORK
/ LOW complexity
Affected Products (1)
Intranet Del Monterroso
Affected Vendors
References (8)
Permissions Required
https://vuldb.com/?ctiid.252717
Permissions Required
https://vuldb.com/?id.252717
Permissions Required
https://vuldb.com/?ctiid.252717
Permissions Required
https://vuldb.com/?id.252717
23
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal