CVE-2019-25528: Inout EasyRooms Ultimate Edition v1.0 SQL Injection via search
Published Mar 12, 2026
·Updated
Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the property1 parameter. Attackers can send POST requests to the search/searchdetailed endpoint with malicious SQL payloads to extract sensitive data or modify database contents.
Affected Software
2 affected components
Inout EasyRooms Ultimate Edition=1.0
Inoutscripts Inout Homestay=1.0
Event History
Mar 12, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-25528?
CVE-2019-25528 has a medium severity due to its SQL injection vulnerability.
2
How do I fix CVE-2019-25528?
To fix CVE-2019-25528, ensure proper input validation and use prepared statements to prevent SQL injection.
3
What software is affected by CVE-2019-25528?
CVE-2019-25528 affects Inout EasyRooms Ultimate Edition version 1.0.
4
Can CVE-2019-25528 be exploited remotely?
Yes, CVE-2019-25528 can be exploited remotely by unauthenticated attackers.
5
What type of vulnerability is CVE-2019-25528?
CVE-2019-25528 is classified as an SQL injection vulnerability.