Ghostwire

CVE-2019-25703: ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to...

HIGH CVSS 7.1 Exploit Available

Published: April 12, 2026 | Last Modified: April 12, 2026

Description

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References