JPortal is susceptible to SQL injection attacks and also stores the administrator password in the clear.