SQL Injection Vulnerabilities in eNdonesia Portal 8.7 by eNdonesia
CVE-2018-25405
8.8HIGH
What is CVE-2018-25405?
eNdonesia Portal 8.7 is susceptible to multiple SQL injection flaws, enabling unauthenticated attackers to run arbitrary SQL commands via malicious inputs in various parameters such as artid, cid, did, contid, and aboutid through the mod.php interface. This vulnerability can lead to the unauthorized exposure of sensitive database information, including user credentials, database names, and version details, posing a significant risk to data security.
Affected Version(s)
eNdonesia Portal 8.7
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Ihsan Sencan
