← Back to browse · API

CVE-2019-5151

Severity
CRITICAL
CVSS
10.0
EPSS
0.02265
Risk score
40.79
CISA KEV
No
PoC
No
Published
2019-10-31
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14756, GHSA-5Q9W-CM7F-C554
Products
YouPHPTube:YouPHPTube YouPHPTube 7.7 commit b22e81d25b2a570f4867ea5dce5153ba4c76cc2d (Oct 15th 2019)
Sources
euvd EUVD-2019-14756

Description

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

References