CVE-2019-25431Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through POST requests to extract sensitive data using boolean-based blind and time-based blind techniques, or write files to the server using INTO OUTFILE statements.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVETodo@CveTodo
    Disclosure

    **CVE-2019-25431** pertains to an SQL injection vulnerability present in **delpino73 Blue-Smiley-Organizer 1.32**. The flaw resides specifically within the handling of the `datetime` parameter in POST requests. This vulnerability allows unauthenticated attackers to craft malicious SQL queries, potentially leading to data extraction, data manipulation, or server compromise. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #SQLInjection https://cvetodo.com/cve/CVE-2019-25431

    Post summary

    The post announces an SQL injection vulnerability in delpino73 Blue‑Smiley‑Organizer 1.32 that permits unauthenticated attackers to manipulate data and potentially compromise the server.

    0000025
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25431 delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database qu… https://www.cve.org/CVERecord?id=CVE-2019-25431

    Post summary

    The message discloses an SQL injection vulnerability in Blue‑Smiley‑Organizer 1.32 that allows unauthenticated attackers to manipulate the database via the datetime parameter.

    0000055
    56.4K followersView on X

Explore more