SQL Injection vulnerability in Chyrp v.2.5.2 and before allows a remote attacker to obtain sensitive information via the Admin.php component
References
| Link | Resource |
|---|---|
| https://github.com/chyrp/chyrp | Product |
| https://github.com/chyrp/chyrp/blob/768dd2f7/includes/controller/Admin.php#L1482 | Product |
| https://swetha-subramanian6.github.io/web%20security/cve/chyrp-sqli-cve/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-16 18:16
Updated : 2026-06-17 10:00
NVD link : CVE-2025-69768
Mitre link : CVE-2025-69768
CVE.ORG link : CVE-2025-69768
JSON object : View
Products Affected
chyrp
- chyrp
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
