SQL Injection Vulnerability in DM Corporative CMS by DMACROWEB
CVE-2025-40654
9.3CRITICAL
What is CVE-2025-40654?
A SQL injection vulnerability exists in DM Corporative CMS, allowing attackers to manipulate SQL queries. By exploiting this flaw, attackers can retrieve, create, update, and delete database entries using the 'name' and 'cod' parameters in the /antbuspre.asp file. This vulnerability poses a significant threat to data integrity and can be leveraged to execute unauthorized commands on the database.
Affected Version(s)
DM Corporative CMS 0 < 2025.01