eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and version information.
Metrics
Affected Vendors & Products
References
History
Sat, 30 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database credentials, usernames, and version information. | |
| Title | eNdonesia Portal 8.7 SQL Injection via mod.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-30T14:55:14.125Z
Reserved: 2026-05-30T12:17:18.007Z
Link: CVE-2018-25406
No data.
Status : Received
Published: 2026-05-30T16:17:00.303
Modified: 2026-05-30T16:17:00.303
Link: CVE-2018-25406
No data.
OpenCVE Enrichment
Updated: 2026-05-30T16:30:27Z