CVE-2019-25532 describes an SQL injection vulnerability in Netartmedia Jobs Portal version 6.1, allowing unauthenticated attackers to manipulate database queries. This high-severity flaw (CVSS 8.2) has a network-based attack vector and low complexity, requiring a crafted POST request to the Email parameter in loginaction.php. Successful exploitation can lead to high confidentiality impact, enabling sensitive database information extraction, and low integrity impact, such as authentication bypass. There is currently no evidence of active exploitation, no public exploit code available in common repositories like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Netartmedia | Netartmedia Jobs Portal | 6.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.