An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
CVE-2018-19925
- No CVSS published and no exploitation signals yet
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
Internet exposure
The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.
- CVSS v3
- —
- EchelonGraph score
- Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
December 6, 2018
Last Modified
June 17, 2026
References (2)
- cve@mitrehttps://github.com/Venan24/SCMS/issues/3
- af854a3a-2127-422b-91ae-364da2661108https://github.com/Venan24/SCMS/issues/3
Vendor Advisories for CVE-2018-19925
Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Related CVEs
Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.
Frequently asked(3)
What is CVE-2018-19925?
When was CVE-2018-19925 disclosed?
How do I remediate CVE-2018-19925?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2018-19925
Is Your Infrastructure Affected by CVE-2018-19925?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.