SQL Injection Vulnerability in DM Corporative CMS by DMACROWEB
CVE-2025-40656

9.3CRITICAL

Key Information:

Vendor

Dmacroweb

Vendor
CVE Published:
10 June 2025

What is CVE-2025-40656?

A SQL injection flaw has been discovered in DM Corporative CMS, which enables attackers to execute unauthorized database commands through the 'cod' parameter in the /administer/node-selection/data.asp endpoint. This vulnerability can potentially allow attackers to retrieve, create, update, or delete sensitive information from the database, posing significant risks to data integrity and confidentiality.

Affected Version(s)

DM Corporative CMS 0 < 2025.01

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oscar Atienza
.