SQL Injection Vulnerability in appRain CMF by appRain
CVE-2025-41032
8.7HIGH
What is CVE-2025-41032?
An SQL injection vulnerability was identified in appRain CMF version 4.0.5, allowing attackers to interact maliciously with the underlying database. By exploiting the 'data%5BAdmin%5D%5Busername%5D' parameter in the /apprain/admin/manage/add/ endpoint, an attacker could potentially retrieve sensitive information, create new database records, modify existing data, or delete entries, leading to significant security risks and data integrity issues.
Affected Version(s)
appRain CMF 4.0.5