CVE-2018-25209

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-26 12:16

Updated : 2026-03-26 15:13


NVD link : CVE-2018-25209

Mitre link : CVE-2018-25209

CVE.ORG link : CVE-2018-25209


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')