top of page
perceptive_background_267k.jpg

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated atta…

Published:

11 maart 2026 om 23:00:00

Alert date:

12 maart 2026 om 22:25:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2019-25515 affects Jettweb PHP Hazir Haber Sitesi Scripti V3, containing an authentication bypass vulnerability in the login.php administration panel. Unauthenticated attackers can gain administrative access by submitting crafted SQL syntax using equals signs and 'or' operators as username and password parameters. This SQL injection vulnerability allows complete bypass of authentication controls without requiring valid credentials. The vulnerability provides immediate administrative access to the affected content management system. Exploit code is publicly available on Exploit-DB, increasing the risk of active exploitation.

Technical details

Mitigation steps:

Affected products:

Jettweb PHP Hazir Haber Sitesi Scripti

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page