Filtered by vendor Novismart Subscriptions
Filtered by product Novismart Cms Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-25439 1 Novismart 1 Novismart Cms 2026-02-23 8.2 High
NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.