Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.
History

Tue, 24 Mar 2026 11:45:00 +0000

Type Values Removed Values Added
Description Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.
Title Inout Article Base CMS Lastest SQL Injection via portalLogin.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-24T11:27:12.125Z

Reserved: 2026-03-24T11:03:56.474Z

Link: CVE-2019-25640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-24T12:16:05.193

Modified: 2026-03-24T12:16:05.193

Link: CVE-2019-25640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.