SQL Injection Vulnerability in appRain CMF by appRain
CVE-2025-41033
8.7HIGH
What is CVE-2025-41033?
A significant SQL injection vulnerability has been identified in appRain CMF version 4.0.5. This flaw allows attackers to manipulate the database, enabling unauthorized retrieval, creation, updating, and deletion of data through the vulnerable 'data[Page][name]' parameter found in the /apprain/page/manage-dynamic-pages/create endpoint. Such exploits can jeopardize data integrity and confidentiality, posing severe risks to users and organizations relying on this content management framework.
Affected Version(s)
appRain CMF 4.0.5