CVE-2019-25640

HIGH

Inout Article Base CMS Lastest SQL Injection via portalLogin.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25640. PoCs published by Ahmet Ümit BAYRAM.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Inout Article Base CMS via the 'p' and 'u' GET parameters in portalLogin.php. The attack patterns use time-based blind SQLi techniques with XOR and sleep functions to confirm vulnerability.

Description

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

Exploits (1)

exploitdb WORKING POC
by Ahmet Ümit BAYRAM · textwebappsphp
https://www.exploit-db.com/exploits/46593

The exploit demonstrates SQL injection vulnerabilities in Inout Article Base CMS via the 'p' and 'u' GET parameters in portalLogin.php. The attack patterns use time-based blind SQLi techniques with XOR and sleep functions to confirm vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Inout Article Base CMS (Latest version as of 2019)
No auth needed
Prerequisites: Access to the target URL · Valid 'd' parameter value
devstral-2 · analyzed Mar 24, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-46593
https://www.exploit-db.com/exploits/46593
Product product
Official Product Homepage
https://www.inoutscripts.com/products/inout-article-base/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Inout Article Base CMS Lastest SQL Injection via portalLogin.php
https://www.vulncheck.com/advisories/inout-article-base-cms-lastest-sql-injection-via-portallogin-php

Scores

CVSS v3 8.2
EPSS 0.0033
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Inoutscripts/Inout Article Base CMS
Published Mar 24, 2026
Tracked Since Mar 24, 2026