microASP Portal+ CMS SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in microASP Portal+ CMS. This issue allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the 'explode_tree' parameter of 'pagina.phtml'. Exploitation of this vulnerability enables attackers to extract sensitive database information, such as the current database name, using crafted SQL injection payloads that leverage the 'extractvalue' and 'concat' functions.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation.

Reproduction

To reproduce this vulnerability, send a request to 'pagina.phtml' with the 'explode_tree' parameter. Inject a SQL payload that uses the 'extractvalue' and 'concat' functions to extract database information. The current database name can be retrieved by concatenating it with a custom string, such as 'sx0u:'.

Added: Feb 22, 2026, 2:22 PM
Updated: Feb 22, 2026, 2:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.