PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.
References
| Link | Resource |
|---|---|
| https://sourceforge.net/projects/pilus/ | Product |
| https://www.exploit-db.com/exploits/46368 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/piluscart-sql-injection-via-send-parameter | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-05 21:16
Updated : 2026-07-24 22:10
NVD link : CVE-2019-25672
Mitre link : CVE-2019-25672
CVE.ORG link : CVE-2019-25672
JSON object : View
Products Affected
kartatopia
- piluscart
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
