Back

CVE-2019-5151

CRITICAL

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

Published: Oct 31, 2019 Modified: Jun 17, 2026
CWE-89 CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: LOW Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H

Affected Products (1)

Vendor Product Version
youphptube youphptube 7.7

GitHub Security Advisory GHSA-5q9w-cm7f-c554

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.27%

Top 18% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub