Confirms that FreeSMS interpolates the login password field directly into a SQL query without escaping. A time-based blind SQL injection payload (SLEEP) proves an attacker can execute arbitrary database commands without authentication, enabling full database extraction and account takeover.
Is your app exploitable through CVE-2019-25506?
Scan your domain free