CVE-2018-25176 PUBLISHED

Alive Parish 2.0.4 SQL Injection and Arbitrary File Upload

Assigner: VulnCheck
Reserved: 06.03.2026 Published: 06.03.2026 Updated: 06.03.2026

Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the images/uploaded directory for remote code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor Demo
Product Alive Parish
Versions
  • Version 2.0.4 is affected

Credits

  • Ihsan Sencan finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE