CVE-2018-25209

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
26/03/2026
Last modified:
26/03/2026

Description

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.