PatchSiren

ASP-CMS Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ASP-CMS Project CVE published 2026-08-13

CVE-2019-25765

CVE-2019-25765 is a SQL injection vulnerability in the commentList.asp endpoint of ASP-CMS. The vulnerability allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. This vulnerability was fir [truncated]