A vulnerability labeled as critical has been found in ImpressCMS 1.3.11. Impacted is an unknown function of the file admin.php of the component POST Request Handler. Executing a manipulation of the argument bid can lead to sql injection.
This vulnerability is registered as CVE-2019-25703. It is possible to launch the attack remotely. Furthermore, an exploit is available.