CVE-2019-25528 is a critical SQL injection vulnerability found in Inout EasyRooms Ultimate Edition v1.0, part of the inoutscripts inout_homestay product family. Rated 9.1 CRITICAL, this flaw allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'property1' parameter in POST requests to the search/searchdetailed endpoint. Successful exploitation could lead to high confidentiality and integrity impacts, enabling attackers to extract sensitive data or modify database contents. Despite its severity, there is currently no evidence of active exploitation, public exploit code availability, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:inoutscripts:inout_homestay:1.0:*:*:*:ultimate:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.