Learn about CVE-2019-5150, a high-severity SQL injection vulnerability in YouPHPTube 7.7. Understand the impact, affected systems, exploitation mechanism, and mitigation steps.
YouPHPTube 7.7 has a vulnerability that can be exploited for SQL injection when the "VideoTags" plugin is activated. This could lead to denial of service, database extraction, local file inclusion, and potential code execution.
Understanding CVE-2019-5150
This CVE involves a high-severity SQL injection vulnerability in YouPHPTube 7.7, impacting network-based attack complexity and availability.
What is CVE-2019-5150?
SQL injection vulnerability in YouPHPTube 7.7
Triggered by an unauthenticated HTTP request with the "VideoTags" plugin
Allows attackers to execute malicious SQL queries
Potential outcomes include denial of service, data extraction, file inclusion, and code execution
The Impact of CVE-2019-5150
Base score of 8.9 (High severity) based on CVSS v3.1
High impact on confidentiality and availability
Low impact on integrity
No privileges required for exploitation
Attack vector via network with no user interaction
Technical Details of CVE-2019-5150
This section provides detailed technical information about the vulnerability.
Vulnerability Description
SQL injection vulnerability in YouPHPTube 7.7
Exploitable when the "VideoTags" plugin is active
Allows attackers to inject and execute malicious SQL commands