Security Advisory
CVE-2019-25640
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the p and u parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.