Junglewise Threat Intelligence

CVE-2018-25405: eNdonesia Portal SQL injection in mod.php

CVE-2018-25405 · Severity: high · CVSS 8.2 · Published 2026-05-30

Technologies: eNdonesia Portal. Vendors: eNdonesia.

Executive brief

eNdonesia Portal is a web-based content management system. A security flaw in the software allows unauthenticated attackers to run unauthorized database commands. This could lead to the theft of sensitive information, including user credentials, database names, and system configuration details.

Technical details

Multiple SQL injection vulnerabilities exist in eNdonesia Portal 8.7 within the 'mod.php' component. The vulnerability is caused by improper neutralization of special elements in several HTTP GET parameters, specifically 'artid', 'cid', 'did', 'contid', and 'aboutid'. An unauthenticated remote attacker can exploit these flaws by sending specially crafted requests to the vulnerable script. Successful exploitation allows the attacker to execute arbitrary SQL commands in the context of the application's database, enabling the extraction of sensitive data such as database schemas, version information, and user credentials. Public exploit code (PoC) is available via Exploit-DB.

Affected products

  • eNdonesia eNdonesia Portal 8.7

Timeline

  • 2018-10-21: other: Vulnerability discovered and PoC developed by researcher
  • 2018-10-22: disclosed: Exploit published on Exploit-DB
  • 2026-05-30: advisory: CVE published and NVD record created

References

Related threats