SQL Injection Vulnerability in DM Corporative CMS by DM Acroweb
CVE-2025-40657

9.3CRITICAL

Key Information:

Vendor

Dmacroweb

Vendor
CVE Published:
10 June 2025

What is CVE-2025-40657?

A SQL injection vulnerability has been identified in DM Corporative CMS that poses a significant risk to database integrity. This flaw allows attackers to execute malicious SQL code through the 'codform' parameter in the '/modules/forms/collectform.asp' file. As a result, an attacker could access sensitive data, modify database records, or even delete critical information. Organizations using this CMS should assess their security posture and apply necessary patches or mitigations to safeguard their databases from potential exploitation.

Affected Version(s)

DM Corporative CMS 0 < 2025.01

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oscar Atienza
.