CVE-2019-25640 identifies SQL injection vulnerabilities within Inout Article Base CMS, enabling unauthenticated attackers to manipulate database queries. These flaws, rated with a CVSS score of 8.2 (HIGH), allow remote attackers to extract sensitive database information and potentially compromise data integrity through XOR-based payloads in GET requests to portalLogin.php. Despite the high severity, there is currently no evidence of active exploitation, public exploit code availability, or significant community discussion, and it is not listed in the CISA Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Inoutscripts | Inout Article Base CMS | All Versions ImpactedCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.