Junglewise Threat Intelligence

CVE-2019-25675: Arca Solutions eDirectory SQL injection and auth bypass

CVE-2019-25675 · Severity: high · CVSS 8.2 · Published 2026-04-05

Executive brief

eDirectory, a platform used to build business directories and membership websites, contains security flaws that allow unauthorized individuals to gain full administrative access. By exploiting these flaws, an attacker can bypass login screens and read sensitive internal files from the server. This could lead to a total compromise of the website, exposure of member data, and theft of proprietary source code.

Technical details

eDirectory (up to version 1.0) is vulnerable to multiple SQL injection flaws, most notably in the 'key' parameter of the /sitemgr/login.php endpoint. An unauthenticated attacker can use a UNION-based SQL injection to manipulate the authentication logic and gain administrative session cookies. Once authenticated, the attacker can exploit a secondary vulnerability in language_file.php via the 'language_id' parameter to perform arbitrary file disclosure. This allows for the reading of sensitive PHP source files from the server. The vulnerability was originally reported in 2019 and affects all versions including 1.0; no official patch was confirmed in the advisory text.

Affected products

  • Arca Solutions eDirectory All versions up to and including 1.0

Timeline

  • 2019-02-19: disclosed: Initial exploit code published to Exploit-DB
  • 2019-03: other: Vulnerability reported to vendor with no response
  • 2026-04-05: advisory: NVD/VulnCheck advisory published

References