CVE-2018-25407

HIGH

eNdonesia Portal 8.7 SQL Injection via mod.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25407. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This is a functional SQL injection exploit for eNdonesia Portal 8.7, demonstrating multiple vulnerable parameters in the 'mod.php' script. The PoC includes crafted HTTP requests that extract database information, user credentials, and version details via error-based SQLi techniques.

Description

eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters across publisher, diskusi, galeri, content, and about modules to extract database information including usernames, database names, and version details.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45654

This is a functional SQL injection exploit for eNdonesia Portal 8.7, demonstrating multiple vulnerable parameters in the 'mod.php' script. The PoC includes crafted HTTP requests that extract database information, user credentials, and version details via error-based SQLi techniques.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: eNdonesia Portal 8.7
No auth needed
Prerequisites: target running eNdonesia Portal 8.7 with exposed mod.php
devstral-2 · analyzed May 30, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-45654
https://www.exploit-db.com/exploits/45654
Product product
Official Product Homepage
http://www.endonesia.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: eNdonesia Portal 8.7 SQL Injection via mod.php
https://www.vulncheck.com/advisories/endonesia-portal-sql-injection-via-mod-php-3

Scores

CVSS v3 8.2
EPSS 0.0027
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Endonesia/eNdonesia Portal 8.7
Published May 30, 2026
Tracked Since May 30, 2026