SQL Injection Vulnerability in DM Corporative CMS by DMACROWEB
CVE-2025-40656
9.3CRITICAL
What is CVE-2025-40656?
A SQL injection flaw has been discovered in DM Corporative CMS, which enables attackers to execute unauthorized database commands through the 'cod' parameter in the /administer/node-selection/data.asp endpoint. This vulnerability can potentially allow attackers to retrieve, create, update, or delete sensitive information from the database, posing significant risks to data integrity and confidentiality.
Affected Version(s)
DM Corporative CMS 0 < 2025.01