CVE-2019-25541 HIGH

CVE-2019-25541: Netartmedia PHP Mall 4.1 Multiple SQL Injection

Vendor Netartmedia
Product Netartmedia PHP Mall
Weakness CWE-89 · SQLi
Published March 12, 2026
Last update March 12, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract sensitive database information.

Key dates

Disclosure timeline

March 12, 2026 CVE published
March 12, 2026 Record updated