CVE-2019-25765 HIGH

CVE-2019-25765: ASP-CMS SQL Injection via commentList.asp id Parameter

Vendor Asp-Cms Project
Product ASP-CMS
Weakness CWE-89 · SQLi
Published August 13, 2026
Last update August 13, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated

Related vulnerabilities

04Related CVE