Junglewise Threat Intelligence

CVE-2018-25414: AiOPMSD SQL injection in multiple PHP components

CVE-2018-25414 · Severity: high · CVSS 8.2 · Published 2026-05-30

Technologies: Hayinfx All in one pack Online Movie Streaming. Vendors: Hayinfx.

Executive brief

AiOPMSD is a PHP-based content management system used to host and manage movie streaming websites. A security flaw allows unauthenticated attackers to gain unauthorized access to the underlying database. This could result in the theft of sensitive information, including user credentials, database structures, and server configuration details.

Technical details

An SQL injection vulnerability exists in AiOPMSD Final 1.0.0 due to improper neutralization of user-supplied input in several PHP components. While the primary advisory highlights the 'actor' parameter in actor.php, exploit research indicates the vulnerability also affects search.php (q parameter), director.php (director parameter), and several others including country.php, quality.php, year.php, genre.php, and watch.php. An unauthenticated remote attacker can send crafted GET requests containing SQL payloads to these endpoints. Successful exploitation allows for the extraction of sensitive data from the MySQL database, such as database version, user accounts, and schema information. No patch is currently known for this legacy software.

Affected products

  • hayinfx All in one pack Online Movie Streaming (AiOPMSD) 1.0.0 Final

Timeline

  • 2017-09-05: other: Last known software update (Final version build 4)
  • 2018-10-24: disclosed: Exploit code published on Exploit-DB
  • 2026-05-30: advisory: CVE published and NVD record created

References

Related threats