SQL Injection Vulnerability in appRain CMF by appRain
CVE-2025-41032

8.7HIGH

Key Information:

Vendor

Apprain

Vendor
CVE Published:
4 September 2025

What is CVE-2025-41032?

An SQL injection vulnerability was identified in appRain CMF version 4.0.5, allowing attackers to interact maliciously with the underlying database. By exploiting the 'data%5BAdmin%5D%5Busername%5D' parameter in the /apprain/admin/manage/add/ endpoint, an attacker could potentially retrieve sensitive information, create new database records, modify existing data, or delete entries, leading to significant security risks and data integrity issues.

Affected Version(s)

appRain CMF 4.0.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.
CVE-2025-41032 : SQL Injection Vulnerability in appRain CMF by appRain