CVE-2025-7385
SQL Injection in GOV CMS
Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker.
Versions 4.0 and above are not affected.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Produtos afetados
Concept Intermedia · GOV CMSQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →