CVE-2019-25728: CARE2X

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php, and various module files to extract sensitive database information without authentication.

Affected products

  • CARE2X CARE2X: version 2.7 only

Published 2026-06-04. Last modified 2026-10-06.