CVE-2019-25366

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
22/02/2026
Last modified:
22/02/2026

Description

microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to extract sensitive database information like the current database name.