CVE-2019-25693

Severity CVSS v4.0:
HIGH
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
12/04/2026
Last modified:
12/04/2026

Description

ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive database information including schema names, user credentials, and other confidential data.