CVE-2019-25693 is a SQL injection vulnerability in ResourceSpace 8.6 that affects the collection_edit.php file, allowing authenticated users to inject arbitrary SQL commands through the keywords parameter. Attackers can submit malicious POST requests containing crafted SQL payloads to compromise the integrity of the backend database. The vulnerability carries a CVSS score of 7.1 (HIGH) and requires low attack complexity with network accessibility. The primary impact is confidentiality loss through unauthorized extraction of sensitive database information such as schema structures, user credentials, and other confidential data, with limited integrity compromise. Exploitation requires valid authentication credentials, which moderates the overall risk profile. Current exploitation status indicates this vulnerability is not actively weaponized in the wild, as evidenced by the absence of CVE entries in the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on security hot lists. The EPSS score of 0.000170000 reflects minimal probability of exploitation in real-world scenarios. However, the moderate FAUCET Risk Score of 46.0 suggests organizations should prioritize patching, particularly if they operate ResourceSpace instances with sensitive data and broad user access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.6CPE matchmatch criteria | cpe:2.3:a:montala:resourcespace:8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.