Vulnerability record · CVE-2019-25494 · published 27 February 2026
CVE-2019-25494: Doditsolutions airbnb clone script sql injection vulnerability
Doditsolutions · Airbnb Clone Script
Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.
Description
Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.doditsolutions.com/airbnb-clone-script/ | Product |
| https://www.exploit-db.com/exploits/46616 | ExploitVDB Entry |
| https://www.vulncheck.com/advisories/homey-bnb-sql-injection-authentication-bypass-via-admin-panel | Broken Link |
Track CVE-2019-25494 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-25494), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.