Junglewise Threat Intelligence

CVE-2018-25406: eNdonesia Portal SQL injection in mod.php

CVE-2018-25406 · Severity: high · CVSS 8.2 · Published 2026-05-30

Technologies: eNdonesia Portal. Vendors: eNdonesia.

Executive brief

eNdonesia Portal, a web-based content management system, contains multiple security flaws that allow unauthorized individuals to access its underlying database. By sending specially crafted web requests, an attacker can bypass security controls to steal sensitive information such as user credentials and system configuration details. This could lead to a full compromise of the website's data and unauthorized access to administrative accounts.

Technical details

Multiple SQL injection vulnerabilities exist in eNdonesia Portal 8.7 within the mod.php component. The application fails to properly sanitize several parameters, including artid, cid, did, contid, and aboutid, across the publisher, diskusi, galeri, content, and about modules. An unauthenticated remote attacker can exploit these flaws by sending crafted GET requests to execute arbitrary SQL commands. Successful exploitation allows the attacker to extract sensitive information from the database, including usernames, database credentials, and software version details. Public exploit code is available for this vulnerability.

Affected products

  • eNdonesia eNdonesia Portal 8.7

Timeline

  • 2018-10-21: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-30: advisory: CVE published and NVD record created

References

Related threats