---
id: CVE-2019-25578
title: phpTransformer 2016.9 SQL Injection via GeneratePDF.php
summary: >-
  phpTransformer 2016.9 contains an SQL injection vulnerability that allows
  remote attackers to execute arbitrary SQL queries by injecting malicious code
  through the idnews parameter. Attackers can send crafted GET requests to
  GeneratePDF.…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-89
vendor: Phptransformer
product: phpTransformer
affected:
  - phpTransformer 2016.9
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-23T15:36:53.763977Z'
exploitAvailable: true
published: '2026-03-21'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:17.843Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25578'
references:
  - url: 'https://www.exploit-db.com/exploits/46191'
    label: ExploitDB-46191
  - url: 'http://phptransformer.com/'
    label: Official Product Homepage
  - url: >-
      https://netcologne.dl.sourceforge.net/project/phptransformer/Version%202016.9/release_2016.9.zip
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/phptransformer-sql-injection-via-generatepdf-php
    label: >-
      VulnCheck Advisory: phpTransformer 2016.9 SQL Injection via
      GeneratePDF.php
tags:
  - cve.org
  - exploit-available
epss: 0.00377
epssPercentile: 0.29262
ingestedAt: '2026-10-01T15:48:17.885Z'
---

## Overview

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.

## Affected

- `phpTransformer 2016.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
