SQL Injection Vulnerability in Saurus CMS Community Edition by Saurus
CVE-2025-50567
10CRITICAL
What is CVE-2025-50567?
Saurus CMS Community Edition 4.7.1 features a security vulnerability in its custom DB::prepare() function. It employs the deprecated /e (eval) modifier with preg_replace(). This flaw allows attackers to inject user-controlled SQL statements, potentially enabling arbitrary PHP code execution. This exposure poses significant risks, allowing for unauthorized actions on affected systems.