CVE-2019-25520
Published: 12 March 2026
Summary
CVE-2019-25520 is a high-severity SQL Injection (CWE-89) vulnerability in Jettweb Php Stock News Site Script. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 34.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified are NIST 800-53 SC-7 (Boundary Protection) and SI-10 (Information Input Validation).
Deeper analysis
CVE-2019-25520 is an authentication bypass vulnerability in Jettweb PHP Hazir Haber Sitesi Scripti V1, specifically affecting the administration panel's login form at admingiris.php. The flaw arises from improper SQL query validation (CWE-89), enabling attackers to submit SQL injection payloads in the username and password fields to circumvent authentication checks and access the administrative interface.
Unauthenticated remote attackers can exploit this vulnerability over the network with low complexity and no privileges required, as indicated by the CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Successful exploitation grants administrative access, resulting in high confidentiality impact through potential data exposure and low integrity impact.
Advisories and references, including the Exploit-DB proof-of-concept at https://www.exploit-db.com/exploits/46597 and the Vulncheck advisory at https://www.vulncheck.com/advisories/jettweb-php-hazir-haber-sitesi-scripti-v1-authentication-bypass, document the issue but do not specify patches or mitigations in the provided details.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2019-19800
Vulnerability details
Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and…
more
password fields of the admingiris.php login form to bypass authentication and access the administrative interface.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The vulnerability is an SQL injection in a public-facing web application's admin login, enabling unauthenticated remote exploitation for administrative access.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Requires validation of inputs at entry points like the login form username and password fields to block SQL injection payloads that bypass authentication.
Mandates identification, reporting, and correction of flaws such as the improper SQL query validation enabling authentication bypass.
Enforces boundary protection using mechanisms like web application firewalls to monitor and block SQL injection attempts targeting the administration login form.