Cyber Resilience

CVE-2019-25520

HighPublic PoC

Published: 12 March 2026

Published
12 March 2026
Modified
17 March 2026
KEV Added
Patch
CVSS Score v4 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0043 34.5th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2019-25520 is a high-severity SQL Injection (CWE-89) vulnerability in Jettweb Php Stock News Site Script. Its CVSS base score is 8.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 34.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified are NIST 800-53 SC-7 (Boundary Protection) and SI-10 (Information Input Validation).

Deeper analysis

CVE-2019-25520 is an authentication bypass vulnerability in Jettweb PHP Hazir Haber Sitesi Scripti V1, specifically affecting the administration panel's login form at admingiris.php. The flaw arises from improper SQL query validation (CWE-89), enabling attackers to submit SQL injection payloads in the username and password fields to circumvent authentication checks and access the administrative interface.

Unauthenticated remote attackers can exploit this vulnerability over the network with low complexity and no privileges required, as indicated by the CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Successful exploitation grants administrative access, resulting in high confidentiality impact through potential data exposure and low integrity impact.

Advisories and references, including the Exploit-DB proof-of-concept at https://www.exploit-db.com/exploits/46597 and the Vulncheck advisory at https://www.vulncheck.com/advisories/jettweb-php-hazir-haber-sitesi-scripti-v1-authentication-bypass, document the issue but do not specify patches or mitigations in the provided details.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to gain administrative access by exploiting improper SQL query validation. Attackers can submit SQL injection payloads in the username and…

more

password fields of the admingiris.php login form to bypass authentication and access the administrative interface.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The vulnerability is an SQL injection in a public-facing web application's admin login, enabling unauthenticated remote exploitation for administrative access.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2019-25510Same product: Jettweb Php Stock News Site Script
CVE-2019-25516Same product: Jettweb Php Stock News Site Script
CVE-2019-25517Same product: Jettweb Php Stock News Site Script
CVE-2019-25515Same product: Jettweb Php Stock News Site Script
CVE-2019-25512Same product: Jettweb Php Stock News Site Script
CVE-2019-25519Same product: Jettweb Php Stock News Site Script
CVE-2019-25511Same product: Jettweb Php Stock News Site Script
CVE-2019-25518Same product: Jettweb Php Stock News Site Script
CVE-2019-25513Same product: Jettweb Php Stock News Site Script
CVE-2019-25514Same product: Jettweb Php Stock News Site Script

Affected Assets

jettweb
php stock news site script
1

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires validation of inputs at entry points like the login form username and password fields to block SQL injection payloads that bypass authentication.

prevent

Mandates identification, reporting, and correction of flaws such as the improper SQL query validation enabling authentication bypass.

prevent

Enforces boundary protection using mechanisms like web application firewalls to monitor and block SQL injection attempts targeting the administration login form.

References