Two vulnerabilities in phpTransformer 2016.9 have been documented, exposing the platform to remote attacks that can disclose sensitive data. CVE-2019-25579 is a directory traversal flaw in the jQueryFileUploadmaster server endpoint that lets unauthenticated attackers read arbitrary files by manipulating a path parameter with traversal sequences such as ../../../../../../. The issue is classified as CWE-22, and the published scoring indicates a high confidentiality impact without corresponding integrity or availability effects.
A second issue, CVE-2019-25578, affects GeneratePDF.php and allows SQL injection through the idnews parameter in crafted GET requests. An attacker could use the flaw to run arbitrary SQL queries, extract database contents, or alter application query behavior. Both CVE records were published with references to Exploit-DB and a VulnCheck advisory, highlighting that phpTransformer 2016.9 contains multiple remotely exploitable weaknesses affecting both file access and backend database security.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry documented a directory traversal vulnerability in phpTransformer 2016.9 that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter sent to the jQueryFileUploadmaster endpoint with traversal sequences. The record states it was received by disclosure@vulncheck.com and includes CWE-22 classification, CVSS vectors, and references including Exploit-DB and a VulnCheck advisory.
A CVE entry documented an SQL injection vulnerability in phpTransformer 2016.9 affecting the idnews parameter in GeneratePDF.php, which can be exploited remotely via crafted GET requests. The record states it was received by disclosure@vulncheck.com and includes CVSS scoring, CWE classification, and references to Exploit-DB and a VulnCheck advisory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.