CVE-2019-25486 identifies an unauthenticated SQL injection vulnerability in Varient version 1.6.1. This flaw allows attackers to manipulate database queries by injecting SQL code through the user_id parameter in POST requests, enabling authentication bypass and the extraction of sensitive database information. Rated with a CVSS score of 8.2 (HIGH), it presents a significant risk due to its network-based attack vector and low attack complexity. Despite its severity, there is currently no evidence of active exploitation, public exploit code availability, or notable community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Varient | Varient SQL Inj. | 1.6.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.