SQL Injection Vulnerability in SemCms from SemCMS
CVE-2025-51657

5.4MEDIUM

Key Information:

Vendor

SemCMS

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-51657?

A SQL injection vulnerability was identified in SemCms v5.0, allowing attackers to manipulate SQL queries through the lgid parameter in the SEMCMS_Link.php file. This flaw can lead to unauthorized database access, data leakage, and potential system compromise, making it imperative for users of SemCms to apply necessary security measures.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.