CVE-2019-18662 is a critical SQL Injection vulnerability affecting YouPHPTube versions through 7.7, specifically within the Live Chat plugin. An attacker can exploit unsanitized user input in the live_stream_code POST parameter to execute arbitrary SQL queries, potentially leading to the disclosure of sensitive database information. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network without authentication or user interaction, allowing for full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high severity warrants immediate patching if the Live Chat plugin is enabled.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.7CPE matchmatch criteria | cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.