---
id: CVE-2019-25505
title: Tradebox 5.4 SQL Injection via symbol Parameter
summary: >-
  Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated
  attackers to manipulate database queries by injecting SQL code through the
  symbol parameter. Attackers can send POST requests to the monthly_deposit
  endpoint …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Bdtask
product: Tradebox
affected:
  - Tradebox 5.4
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-03-05T16:00:09.640118Z'
exploitAvailable: true
published: '2026-03-04'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:17.154Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25505'
references:
  - url: 'https://www.exploit-db.com/exploits/46671'
    label: ExploitDB-46671
  - url: >-
      https://www.vulncheck.com/advisories/tradebox-sql-injection-via-symbol-parameter
    label: 'VulnCheck Advisory: Tradebox 5.4 SQL Injection via symbol Parameter'
tags:
  - cve.org
  - exploit-available
epss: 0.00287
epssPercentile: 0.19219
ingestedAt: '2026-10-01T15:48:17.887Z'
---

## Overview

Tradebox 5.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the symbol parameter. Attackers can send POST requests to the monthly_deposit endpoint with malicious symbol values using boolean-based blind, time-based blind, error-based, or union-based SQL injection techniques to extract sensitive database information.

## Affected

- `Tradebox 5.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
