SQL Injection Vulnerability in SemCms by SemCMS Inc.
CVE-2025-51658

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 July 2025

What is CVE-2025-51658?

SemCms version 5.0 has been identified with a SQL injection vulnerability that can be exploited via the ID parameter in the SEMCMS_InquiryView.php file. This type of vulnerability allows attackers to manipulate database queries by injecting malicious SQL code, potentially leading to unauthorized data access or manipulation. It is crucial for users and administrators of SemCms to implement appropriate security measures to mitigate this risk and protect sensitive data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.