SQL Injection Vulnerability in EngineerCMS by Engineer
CVE-2025-44831

9.8CRITICAL

Key Information:

Vendor

Engineer

Vendor
CVE Published:
13 May 2025

What is CVE-2025-44831?

The EngineerCMS platform, specifically versions 1.02 through 2.0.5, is vulnerable to SQL injection through the /project/addproject interface. This flaw allows attackers to manipulate SQL queries by injecting arbitrary code, potentially leading to unauthorized access to the backend database. Exploitation of this vulnerability may result in data leakage, unauthorized modifications, or further attacks on the application and its underlying infrastructure. Web developers and system administrators using these versions of EngineerCMS should apply security patches immediately and consider additional security measures to safeguard their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.