CVE-2018-25187
Tina4 Stack 1.0.3 SQL Injection and Database File Download
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu endpoint to manipulate database queries.
| CWE | CWE-89 |
| Vendor | tina4 |
| Product | tina4 stack |
| Published | Mar 6, 2026 |
| Last Updated | Mar 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for tina4 tina4 stack
Be the first to know when new high vulnerabilities affecting tina4 tina4 stack are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Tina4 / Tina4 Stack
1.0.3
References
Credits
Ihsan Sencan