Junglewise Threat Intelligence

CVE-2018-25411: MGB OpenSource Guestbook SQL injection in email.php

CVE-2018-25411 · Severity: high · CVSS 8.2 · Published 2026-05-30

Executive brief

MGB OpenSource Guestbook is a PHP-based application used to host visitor comments and feedback on websites. A security flaw in the software allows unauthorized individuals to access the underlying database without a password. This could lead to the theft of sensitive information, including user data and system configuration details, potentially compromising the entire website's security.

Technical details

A SQL injection vulnerability exists in MGB OpenSource Guestbook version 0.7.0.2 and prior. The flaw is located in the 'id' parameter of the email.php script, which fails to properly sanitize user-supplied input before using it in a database query. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing SQL payloads. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive data such as database table names, column names, and stored user information. While the vendor has released newer versions (e.g., 0.7.1.1) that address various bugs and PHP compatibility, users should ensure they are running a version that mitigates this 2018-era vulnerability.

Affected products

  • MGB MGB OpenSource Guestbook 0.7.0.2 and earlier

Timeline

  • 2018-10-23: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-30: advisory: CVE record published and enriched by VulnCheck

References