---
id: CVE-2019-25580
title: >-
  ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated
  attackers to execute arbitrary SQL queries by injecting malicious code through
  the IMG parameter
summary: >-
  ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated
  attackers to execute arbitrary SQL queries by injecting malicious code through
  the IMG parameter. Attackers can send GET requests to pdfstream.php,
  imagestrea…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-434
vendor: owndms
product: owndms
affected:
  - owndms <= 4.7
published: '2026-03-21'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25580'
references:
  - url: 'http://www.owndms.com/'
    label: disclosure@vulncheck.com
  - url: 'https://datapacket.dl.sourceforge.net/project/owndms/owndms_47.zip'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46168'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/owndms-sql-injection-via-pdfstream-php-imagestream-php
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00324
epssPercentile: 0.23345
ingestedAt: '2026-10-07T08:20:03.904Z'
---

## Overview

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names.

## Affected

- `owndms <= 4.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
