Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

microASP Portal+ CMS exposes sensitive data through SQL injection

CVE-2019-25366
Summary

The microASP Portal+ CMS software contains a security flaw that allows attackers to access sensitive database information without a password. This can happen if attackers send a specific type of request to the software. To stay secure, update to the latest version of the software as soon as possible.

Original title
microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Atta...
Original description
microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to extract sensitive database information like the current database name.
nvd CVSS3.1 8.2
nvd CVSS4.0 8.8
Vulnerability type
CWE-89 SQL Injection
Published: 22 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026