{"id":"CVE-2019-25100","details":"A vulnerability was found in happyman twmap. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file twmap3/data/ajaxCRUD/pointdata2.php. The manipulation of the argument id leads to sql injection. Upgrading to version v2.9_v4.31 is able to address this issue. The identifier of the patch is babbec79b3fa4efb3bd581ea68af0528d11bba0c. It is recommended to upgrade the affected component. The identifier VDB-217645 was assigned to this vulnerability.","modified":"2026-07-08T05:55:56.475264445Z","published":"2023-01-08T11:15:10.130Z","database_specific":{"unresolved_ranges":[{"vendor_product":"twmap_project:twmap","cpes":["cpe:2.3:a:twmap_project:twmap:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"2.91_4.31"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://github.com/happyman/twmap/releases/tag/v2.9_v4.31"},{"type":"ADVISORY","url":"https://vuldb.com/?ctiid.217645"},{"type":"ADVISORY","url":"https://vuldb.com/?id.217645"},{"type":"REPORT","url":"https://github.com/happyman/twmap/issues/42"},{"type":"FIX","url":"https://github.com/happyman/twmap/commit/babbec79b3fa4efb3bd581ea68af0528d11bba0c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/happyman/twmap","events":[{"introduced":"0"},{"fixed":"babbec79b3fa4efb3bd581ea68af0528d11bba0c"},{"fixed":"64ec51bd6c83453d1d3b884d549143608c850d62"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.82_v4.25","v2.81_v4.20","v2.81_v4.16","v2.81_4.15","v2.81_4.14","v2.81_4.12","v2.80_4.12","v2.79_4.03","v2.79_4.02","v2.79_3.99","v2.77_3.97","v2.77_3.93","v2.77_3.86","v2.73_3.85","v2.72_3.81","v2.72_3.8","v2.70_3.8","v2.7_3.76","v2.70_3.76","del"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25100.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}