CVE-2019-25709
Received
Received - Intake
Unauthorized Database Access and Deletion in CF Image Hosting
Publication date: 2026-04-12
Last updated on: 2026-04-23
Assigner: VulnCheck
Description
Description
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codefuture | image_hosting_script | 1.6.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |