Description
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argument change_to_admin leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
In code-projects/anirbandutta9 Content Management System and News-Buzz 1.0 wurde eine kritische Schwachstelle ausgemacht. Hierbei betrifft es unbekannten Programmcode der Datei /admin/users.php. Mittels Manipulieren des Arguments change_to_admin mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
| 2025-06-04: | Advisory disclosed |
| 2025-06-04: | VulDB entry created |
| 2025-06-04: | VulDB entry last update |
Credits
XU17 (VulDB User)
References
github.com/...in/NEWS-BUZZ/sqli_users.php_change_to_admin.md
vuldb.com/?id.311119 (VDB-311119 | code-projects/anirbandutta9 Content Management System/News-Buzz users.php sql injection)
vuldb.com/?ctiid.311119 (VDB-311119 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.589781 (Submit #589781 | code-projects NEWS-BUZZ (News Management System) v1.0 SQL Injection)
github.com/...in/NEWS-BUZZ/sqli_users.php_change_to_admin.md