CVE-2018-25300 HIGH

CVE-2018-25300: XATABoost CMS 1.0.0 SQL Injection via news.php

Vendor Xataboost
Product XATABoost CMS
Weakness CWE-89 · SQLi
Published April 29, 2026
Last update April 30, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

Key dates

Disclosure timeline

April 29, 2026 CVE published
April 30, 2026 Record updated