CVE-2019-25640: Inout Article Base CMS Lastest SQL Injection via portalLogin.php
Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25640?
CVE-2019-25640 has a medium severity level due to its potential for unauthorized SQL injection attacks.
How do I fix CVE-2019-25640?
To fix CVE-2019-25640, update Inout Article Base CMS to the latest version that addresses the SQL injection vulnerability.
What are the potential impacts of CVE-2019-25640?
CVE-2019-25640 can allow attackers to manipulate database queries, potentially leading to data breach and unauthorized access.
Who is affected by CVE-2019-25640?
CVE-2019-25640 affects users of Inout Article Base CMS, particularly those running vulnerable versions.
What are the affected components in CVE-2019-25640?
CVE-2019-25640 specifically affects the portalLogin.php file and the 'p' and 'u' parameters in GET requests.