


Perceptive Security
SOC/SIEM Consultancy

Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated attackers to g…
Published:
11 maart 2026 om 23:00:00
Alert date:
12 maart 2026 om 17:15:30
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2019-25510 affects Jettweb PHP Hazir Haber Sitesi Scripti V2, containing an authentication bypass vulnerability in the administration panel. Unauthenticated attackers can gain administrative access by exploiting improper SQL query validation. The vulnerability allows SQL injection payloads to be submitted in the username and password fields of the admingiris.php login form. This enables complete bypass of authentication mechanisms and unauthorized access to the administrative interface. The vulnerability represents a critical security flaw that provides full administrative control to attackers.
Technical details
Mitigation steps:
Affected products:
Jettweb PHP Hazir Haber Sitesi Scripti
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2019-25510
https://www.exploit-db.com/exploits/46598
https://www.vulncheck.com/advisories/jettweb-php-hazir-haber-sitesi-scripti-v2-authentication-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
