VYPR
High severity8.2NVD Advisory· Published Mar 12, 2026· Updated Apr 15, 2026

CVE-2019-25537

CVE-2019-25537

Description

Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email field to extract sensitive database information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Netartmedia Event Portal 2.0 has a time-based blind SQL injection in the Email parameter of loginaction.php, allowing unauthenticated attackers to extract database information.

Root

Cause

The vulnerability is a time-based blind SQL injection in the Email parameter of loginaction.php. The application fails to properly neutralize special elements used in an SQL command (CWE-89), allowing attackers to inject arbitrary SQL code. This issue affects Netartmedia Event Portal version 2.0 and earlier [1].

Exploitation

An unauthenticated attacker can exploit this by sending a POST request to loginaction.php with a malicious payload in the Email field. The exploit uses time-based detection, such as the SLEEP() function, to infer database information byte by byte. No authentication or special privileges are required [1][2].

Impact

Successful exploitation allows an attacker to extract sensitive data from the database, including user credentials, personal information, and other stored data. The CVSS v4 vector indicates high confidentiality impact (VC:H), with low integrity impact (VI:L) [1].

Mitigation

As of the advisory, no official patch has been confirmed. Users should consider upgrading to a patched version if available, or implement input validation and parameterized queries to prevent SQL injection. The vulnerability has been publicly disclosed via Exploit-DB [2].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.