CVE-2018-25405 HIGH

CVE-2018-25405: eNdonesia Portal 8.7 SQL Injection via mod.php

Vendor Endonesia
Product eNdonesia Portal
Weakness CWE-89 · SQLi
Published May 30, 2026
Last update June 1, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid parameters to extract sensitive database information including usernames, database names, and version details.

Key dates

Disclosure timeline

May 30, 2026 CVE published
June 1, 2026 Record updated