Junglewise Threat Intelligence

CVE-2019-25680: Phpscriptsmall Advance Gift Shop Pro Script SQL injection in search parameter

CVE-2019-25680 · Severity: high · CVSS 8.2 · Published 2026-04-05

Executive brief

Advance Gift Shop Pro Script is a web-based platform used to create and manage online gift shops. A security flaw in the search functionality allows unauthorized individuals to run hidden commands against the website's database. This could lead to the theft of sensitive customer information, website data, or server configuration details.

Technical details

An SQL injection vulnerability exists in Phpscriptsmall Advance Gift Shop Pro Script 2.0.3 due to improper neutralization of special elements in the 's' search parameter. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP GET request containing malicious SQL payloads. Successful exploitation allows the attacker to bypass security controls and execute arbitrary queries, potentially leading to the extraction of sensitive database information such as version details, user credentials, and store data. The vulnerability is confirmed to be exploitable via error-based SQL injection techniques using functions like extractvalue().

Affected products

  • Phpscriptsmall Advance Gift Shop Pro Script 2.0.3

Timeline

  • 2019-02-21: disclosed: Vulnerability discovered by Mr Winst0n
  • 2019-02-25: other: Exploit code published on Exploit-DB
  • 2026-04-05: advisory: CVE-2019-25680 published by NVD/VulnCheck

References