CVE-2018-19925

UNRATEDCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: —

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.

Internet exposure

The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.

CVSS v3
—
EchelonGraph score
Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

December 6, 2018

Last Modified

June 17, 2026

References (2)

Vendor Advisories for CVE-2018-19925

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.

Frequently asked(3)

What is CVE-2018-19925?
CVE-2018-19925 is a publicly disclosed vulnerability published on December 6, 2018. An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/memberorder.php type parameter, related to the Ostate parameter.
When was CVE-2018-19925 disclosed?
CVE-2018-19925 was first published on December 6, 2018, with the most recent update on June 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2018-19925?
No fix for CVE-2018-19925 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2018-19925

Explore →

Is Your Infrastructure Affected by CVE-2018-19925?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.