๐Ÿ” CVE Alert

CVE-2018-25362

HIGH 8.2

Twitter-Clone 1 SQL Injection via follow.php

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
10th

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials.

CWE CWE-89
Vendor fyffe
Product php-twitter-clone
Published May 25, 2026
Last Updated May 26, 2026
Stay Ahead of the Next One

Get instant alerts for fyffe php-twitter-clone

Be the first to know when new high vulnerabilities affecting fyffe php-twitter-clone are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

Fyffe / PHP-Twitter-Clone
1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/45230 github.com: https://github.com/Fyffe/PHP-Twitter-Clone/ vulncheck.com: https://www.vulncheck.com/advisories/twitter-clone-1-sql-injection-via-follow-php

Credits

L0RD