HIGH
ASP-CMS Project
CVE published 2026-08-13
CVE-2019-25765
CVE-2019-25765 is a SQL injection vulnerability in the commentList.asp endpoint of ASP-CMS. The vulnerability allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. This vulnerability was fir [truncated]