


Perceptive Security
SOC/SIEM Consultancy

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through theā¦
Published:
25 maart 2026 om 23:00:00
Alert date:
26 maart 2026 om 13:04:30
Source:
nvd.nist.gov
Web Technologies
CVE-2018-25183 affects Shipping System CMS 1.0, containing an SQL injection vulnerability in the admin login endpoint. Unauthenticated attackers can bypass authentication by injecting malicious SQL code through the username parameter. The vulnerability allows exploitation using boolean-based blind SQL injection techniques via POST requests. Attackers can authenticate without valid credentials by submitting crafted SQL payloads. This represents a critical authentication bypass vulnerability in the content management system.
Technical details
Mitigation steps:
Affected products:
Shipping System CMS 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25183
https://www.exploit-db.com/exploits/44722
https://www.vulncheck.com/advisories/shipping-system-cms-sql-injection-via-admin-login
https://www.wecodex.com/item/view/shipping-system-by-parcel-in-php-and-mysql/4
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
