SQL Injection Vulnerability in appRain CMF by appRain
CVE-2025-41033

8.7HIGH

Key Information:

Vendor

Apprain

Vendor
CVE Published:
4 September 2025

What is CVE-2025-41033?

A significant SQL injection vulnerability has been identified in appRain CMF version 4.0.5. This flaw allows attackers to manipulate the database, enabling unauthorized retrieval, creation, updating, and deletion of data through the vulnerable 'data[Page][name]' parameter found in the /apprain/page/manage-dynamic-pages/create endpoint. Such exploits can jeopardize data integrity and confidentiality, posing severe risks to users and organizations relying on this content management framework.

Affected Version(s)

appRain CMF 4.0.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.