top of page
perceptive_background_267k.jpg

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated atta…

Published:

11 March 2026 at 23:00:00

Alert date:

12 March 2026 at 22:25:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2019-25515 affects Jettweb PHP Hazir Haber Sitesi Scripti V3, containing an authentication bypass vulnerability in the login.php administration panel. Unauthenticated attackers can gain administrative access by submitting crafted SQL syntax using equals signs and 'or' operators as username and password parameters. This SQL injection vulnerability allows complete bypass of authentication controls without requiring valid credentials. The vulnerability provides immediate administrative access to the affected content management system. Exploit code is publicly available on Exploit-DB, increasing the risk of active exploitation.

Technical details

Mitigation steps:

Affected products:

Jettweb PHP Hazir Haber Sitesi Scripti

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page