CVE-2019-25433 | Xoops CMS 2.5.9 gerar_pdf.php cid sql injection (Exploit 46835 / EDB-46835)
A vulnerability labeled as critical has been found in Xoops CMS 2.5.9. This vulnerability affects unknown code of the file gerar_pdf.php. Executing a manipulation of the argument cid can lead to sql injection.
This vulnerability is registered as CVE-2019-25433. It is possible to launch the attack remotely. Furthermore, an exploit is available.