Junglewise Threat Intelligence

CVE-2018-25431: goFrendiAsgard No-CMS SQL injection in manage_privilege export

CVE-2018-25431 · Severity: high · CVSS 7.1 · Published 2026-06-01

Executive brief

No-CMS is a web content management framework based on CodeIgniter. A security flaw in the privilege management component allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive information, including user credentials or administrative data, potentially compromising the entire website.

Technical details

An SQL injection vulnerability exists in No-CMS 1.0 within the 'manage_privilege' export functionality. The root cause is improper neutralization of the 'order_by' parameter in POST requests sent to /nocms/main/manage_privilege/index/export. An authenticated attacker can supply malicious SQL code via the order_by[0] parameter to manipulate backend database queries. This allows for the extraction of sensitive data from the database. The vulnerability is classified as CWE-89 and requires low-level authentication to exploit.

Affected products

  • goFrendiAsgard No-CMS 1.0

Timeline

  • 2018-11-26: disclosed: Initial exploit published on Exploit-DB
  • 2026-06-01: advisory: CVE published and NVD record created

References