CVE-2019-25640Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-24: 2Technical Details · 2026-03-24: 203-24
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2019-25640 Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. … https://www.cve.org/CVERecord?id=CVE-2019-25640 ----- Traducción: CVE-2019-25640 Ino… http://infoflow.cloud`

    Post summary

    The post announces that CVE‑2019‑25640 in the Inout Article Base CMS allows unauthenticated SQL injection via the 'p' and 'u' parameters, but provides no PoC, exploit code, or patch details.

    0000023
    60 followersView on X
  • CVE@CVEnew
    General

    CVE-2019-25640 Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. … https://www.cve.org/CVERecord?id=CVE-2019-25640

    Post summary

    The post identifies CVE‑2019‑25640 as an unauthenticated SQL injection vulnerability in Inout Article Base CMS, but offers no proof of concept, exploit code, active exploitation reports, or mitigation details.

    00000140
    56.8K followersView on X

Explore more