Report: CVE-2019-25486 - Varient 1.6.1 SQL Injection via user_id Parameter

Report: CVE-2019-25486 - Varient 1.6.1 SQL Injection via user_id Parameter

CVE ID :CVE-2019-25486 Published : March 11, 2026, 6:23 p.m. | 1 hour, 2 minutes ago Description :Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_id parameter. Attackers can submit POST requests with crafted SQL payloads in the user_id field to bypass authentication and extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 11, 2026
Impact: SQL injection